Threat Actors Expand Abuse of Legitimate Remote-Access Tools in Multi-Stage Campaigns

· Original article ↗

Summary

Cofense reports rising multi-stage campaigns that use phishing to install legitimate remote-access tools, which then fetch additional RATs or payloads via command-and-control servers. Attackers use the access to maintain persistence and may sell it to other threat actor

Key points

  • Campaigns typically begin with phishing emails linking to spoofed websites that deliver a remote-access tool; attached documents or scripts are less common delivery methods.
  • The initial tool contacts a command-and-control server, which can direct it to download additional RATs or other payloads. Different threat actors may control separate stages.
  • Cofense describes campaigns using tools including GoTo RAT, Datto RMM, SimpleHelp, and ConnectWise; one example also downloaded Heartbeat RM and a utility to hide software from Windows’ uninstall list.
  • Attackers use multi-stage access to maintain persistence and, in some cases, sell access to infected computers and corporate networks as initial access brokers.
  • Cofense reports an upward trend in multi-stage remote-access attacks from January 2025 through March 2026.
  • Because legitimate tools and multiple command-and-control paths can obscure malicious activity, Cofense recommends phishing training, behavioral EDR, an approved-tool list, and analysis of activity in its broader context.

Article Details

Attack Vectors
  • Phishing emails use embedded links to lead recipients to spoofed websites that download legitimate remote access tools configured for attacker access.
  • The article also describes documents with embedded links and, more rarely, attached malicious scripts as initial delivery mechanisms.
  • In ATR 409595, an Adobe Cloud-spoofing email led to GoTo RAT installation; its C2 server then directed it to download ConnectWise RAT.
  • In ATR 409165, a link delivered Datto RMM, which was directed to download ConnectWise RAT.
  • In ATR 408664, a fake invitation led to a SimpleHelp RAT download; its C2 server directed it to download ConnectWise RAT.
  • In ATR 410324, a document-themed email led to ConnectWise RAT installation. Its C2 server directed downloads of Heartbeat RM, another ConnectWise RAT, and a utility that hides software from the Windows uninstall list.
Defensive Notes
  • Train employees to recognize and report phishing; Cofense says trained employees reported the cited examples after they bypassed email security technologies.
  • Use behavioral-based Endpoint Detection and Response to detect malicious activity beyond static file signatures.
  • Maintain a curated list of approved remote access tools so unauthorized deployments can be identified and removed.
  • Assess tool use, processes, and network connections in the context of the full delivery and follow-on activity, rather than treating each legitimate tool in isolation.

MITRE ATT&CK

People

Malware

Products

Related Articles