MITRE ATT&CK Technique
T1219Remote Access Tools
- First Reported
- Aug 5, 2025
- Latest Reported
- Oct 6, 2026
Official Description
An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools create a session between two trusted hosts through a graphical interface, a command line interaction, a protocol tunnel via development or management software, or hardware-level access such as KVM (Keyboard, Video, Mouse) over IP solutions. Desktop support software (usually graphical interface) and remote management software (typically command line interface) allow a user to control a computer remotely as if they are a local user inheriting the user or software permissions. This software is commonly used for troubleshooting, software installation, and system management.(Citation: Symantec Living off the Land)(Citation: CrowdStrike 2015 Global Threat Report)(Citation: CrySyS Blog TeamSpy) Adversaries may similarly abuse response features included in EDR and other defensive tools that enable remote access.
Remote access tools may be installed and used post-compromise as an alternate communications channel for redundant access or to establish an interactive remote desktop session with the target system. It may also be used as a malware component to establish a reverse connection or back-connect to a service or adversary-controlled system.
Installation of many remote access tools may also include persistence (e.g., the software's installation routine creates a [Windows Service](https://attack.mitre.org/techniques/T1543/003)). Remote access modules/features may also exist as part of otherwise existing software (e.g., Google Chrome’s Remote Desktop).(Citation: Google Chrome Remote Desktop)(Citation: Chrome Remote Desktop)
Remote access tools may be installed and used post-compromise as an alternate communications channel for redundant access or to establish an interactive remote desktop session with the target system. It may also be used as a malware component to establish a reverse connection or back-connect to a service or adversary-controlled system.
Installation of many remote access tools may also include persistence (e.g., the software's installation routine creates a [Windows Service](https://attack.mitre.org/techniques/T1543/003)). Remote access modules/features may also exist as part of otherwise existing software (e.g., Google Chrome’s Remote Desktop).(Citation: Google Chrome Remote Desktop)(Citation: Chrome Remote Desktop)
- Tactics
- Command And Control
- Platforms
- Linux, macOS, Windows
- MITRE Version
- 3.0
- Last Modified
- May 12, 2026
Sub-techniques (3)
Reported Context (28)
- CISA warned that ransomware actors abuse legitimate RMM software to reach downstream customer networks. How MSPs Can Secure RMM Software: Eight Controls to Test
- The attackers installed Visual Studio Code's built-in tunnel feature as a service for covert remote access. Warlock Ransomware Group Hits Water and Telecom Operators, Continues Exploiting SharePoint
- ScreenConnect and MeshAgent were deployed to maintain remote control of the compromised system. KMS Auto Abuse Led to Mining, Remote Access Tools and Ransomware-Themed Scareware; APT36 Link Unconfirmed
- Attackers used remote-support and RMM software to obtain or maintain access. ReliaQuest Report Tracks Top Attacker Techniques in June–August 2026
- Threat actors steer victims toward legitimate remote support and remote access tooling, including Quick Assist. ThreatLabz Report: Ransomware Data Theft Surges as Attackers Target High-Impact Employees
CVE (24)
Malware (38)
People (27)
Threat Actors (45)
MITRE ATT&CK (139)
Vendors (59)
Products (135)
Tools (75)
Industries (25)
Countries (23)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.