Threat Actors Expand Abuse of Legitimate Remote-Access Tools in Multi-Stage Campaigns

Summary
Cofense reports rising multi-stage campaigns that use phishing to install legitimate remote-access tools, which then fetch additional RATs or payloads via command-and-control servers. Attackers use the access to maintain persistence and may sell it to other threat actor
Key points
- Campaigns typically begin with phishing emails linking to spoofed websites that deliver a remote-access tool; attached documents or scripts are less common delivery methods.
- The initial tool contacts a command-and-control server, which can direct it to download additional RATs or other payloads. Different threat actors may control separate stages.
- Cofense describes campaigns using tools including GoTo RAT, Datto RMM, SimpleHelp, and ConnectWise; one example also downloaded Heartbeat RM and a utility to hide software from Windows’ uninstall list.
- Attackers use multi-stage access to maintain persistence and, in some cases, sell access to infected computers and corporate networks as initial access brokers.
- Cofense reports an upward trend in multi-stage remote-access attacks from January 2025 through March 2026.
- Because legitimate tools and multiple command-and-control paths can obscure malicious activity, Cofense recommends phishing training, behavioral EDR, an approved-tool list, and analysis of activity in its broader context.
Article Details
- Attack Vectors
- Phishing emails use embedded links to lead recipients to spoofed websites that download legitimate remote access tools configured for attacker access.
- The article also describes documents with embedded links and, more rarely, attached malicious scripts as initial delivery mechanisms.
- In ATR 409595, an Adobe Cloud-spoofing email led to GoTo RAT installation; its C2 server then directed it to download ConnectWise RAT.
- In ATR 409165, a link delivered Datto RMM, which was directed to download ConnectWise RAT.
- In ATR 408664, a fake invitation led to a SimpleHelp RAT download; its C2 server directed it to download ConnectWise RAT.
- In ATR 410324, a document-themed email led to ConnectWise RAT installation. Its C2 server directed downloads of Heartbeat RM, another ConnectWise RAT, and a utility that hides software from the Windows uninstall list.
- Defensive Notes
- Train employees to recognize and report phishing; Cofense says trained employees reported the cited examples after they bypassed email security technologies.
- Use behavioral-based Endpoint Detection and Response to detect malicious activity beyond static file signatures.
- Maintain a curated list of approved remote access tools so unauthorized deployments can be identified and removed.
- Assess tool use, processes, and network connections in the context of the full delivery and follow-on activity, rather than treating each legitimate tool in isolation.
MITRE ATT&CK
T1105 · Ingress Tool TransferAfter installation, initial remote access tools receive C2 instructions to download additional remote access tools and other payloads.T1204.001 · Malicious LinkRecipients are prompted to click phishing-email links, including links presented as an Adobe Cloud update, an invitation, or signed documents.T1204.002 · Malicious FileThe described infection chains depend on a downloaded initial remote access tool executable being run and installed on the victim machine.T1219 · Remote Access ToolsAttackers abuse legitimate remote access tools, including GoTo RAT, Datto RMM, SimpleHelp RAT, and ConnectWise RAT, to control victim machines and deploy further stages.T1566.001 · Spearphishing AttachmentThe article describes attached documents with embedded links and, more rarely, attached malicious scripts as alternative phishing delivery mechanisms.T1566.002 · Spearphishing LinkThe reported attacks commonly start with phishing emails containing links to spoofed or malicious pages that initiate remote access tool downloads.
People
Malware
AsyncRATMulti-stage remote access trojans have been around for quite some time with malware families such as AsyncRAT, Remcos RAT, and XWorm RAT. While these malware families are still in use, in the past year the new trend inRemcos RATremote access trojans have been around for quite some time with malware families such as AsyncRAT, Remcos RAT, and XWorm RAT. While these malware families are still in use, in the past year the new trend inXWormtrojans have been around for quite some time with malware families such as AsyncRAT, Remcos RAT, and XWorm RAT. While these malware families are still in use, in the past year the new trend in multi-stage RATs uses
Products
ConnectWise RATother threat actors. Attackers are using many different legitimate RATs for their attacks, such as ConnectWise RAT, N-Able RAT, SimpleHelp RAT, Datto RMM, and GoTo RAT. Each of these legitimate tools has uniqueDatto RMMmany different legitimate RATs for their attacks, such as ConnectWise RAT, N-Able RAT, SimpleHelp RAT, Datto RMM, and GoTo RAT. Each of these legitimate tools has unique capabilities such as enterprise familiarity,GoTo RATlegitimate RATs for their attacks, such as ConnectWise RAT, N-Able RAT, SimpleHelp RAT, Datto RMM, and GoTo RAT. Each of these legitimate tools has unique capabilities such as enterprise familiarity, cloud hostedHeartbeat RMFigure 8: Document-themed email from ATR 410324 delivered ConnectWise RAT and Heartbeat RM.N-Able RATactors. Attackers are using many different legitimate RATs for their attacks, such as ConnectWise RAT, N-Able RAT, SimpleHelp RAT, Datto RMM, and GoTo RAT. Each of these legitimate tools has unique capabilities suchSimpleHelp RATare using many different legitimate RATs for their attacks, such as ConnectWise RAT, N-Able RAT, SimpleHelp RAT, Datto RMM, and GoTo RAT. Each of these legitimate tools has unique capabilities such as enterprise