Activity timeline
T1219 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 100 reports, and 272 of the 272 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1219 Remote Access Tools is catalogued by MITRE ATT&CK under the Command and Control tactic in the Enterprise matrix. Threadlinqs maps 272 of 2623 tracked threats (10.4%) to it; by severity that is 69 critical, 178 high, 25 medium.
Threats that use T1219 most often also use T1027 Obfuscated Files or Information (143 threats), T1082 System Information Discovery (129 threats), T1685 Disable or Modify Tools (128 threats), T1036 Masquerading (126 threats), T1005 Data from Local System (112 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
93 tracked threat actors appear in the threats that use T1219; the most frequent are MuddyWater (8), Akira (6), Contagious Interview (6), Storm-1567 (6), ShinyHunters (5).
Mitigations
MITRE ATT&CK lists 5 mitigations for T1219.
Data sources
Telemetry that can reveal T1219, per MITRE ATT&CK.
- Drive — Drive Creation
- Network Traffic — Network Connection Creation, Network Traffic Content, Network Traffic Flow
- Process — Process Creation
Threat actors using it
Tracked threats
The 30 most recent of 272 tracked threats that use T1219.
- The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira…high
- Multiple High-Severity Vulnerabilities in TeamViewer Client (CVE-2026-92370, CVE-2026-92368, CVE-2026-92369…high
- GTIG: AI-Era Vulnerability Discovery and Exploitation Surge — In-the-Wild Exploitation of BeyondTrust…critical
- CSuite Phishing Operation Steals Microsoft 365 Sessions via Device-Code Phishing and Deploys…high
- Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect) for Persistent Accesshigh
- North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum Transactions (HashHiding) for Covert C2 Signalinghigh
- ShinyHunters Claims Breach of FBI Jobs Portal (fbijobs.gov) via Alleged Oracle PeopleSoft Zero-Day, Exposing…high
- Microsoft Tracks Storm-2570 Ransomware Affiliate Behind Qilin, DragonForce, Anubis, and BERT Deploymentshigh
- OS-Aware Phishing Kit Fans Fake iCloud Alert into ScreenConnect RMM, Apple ID, and M365 AiTM Harvestershigh
- Sauron Loader: New DLL Side-Loading Malware-as-a-Service Deployed Against German Organizations via ClickFix…high
- Kothamine RAT Abuses Tailscale's Tailcat for Encrypted C2, Distributed via Malicious npm Packageshigh
- Malicious Google Ads campaign delivers browser-locking fake tech support scareware to Windows and Mac usershigh
- SectopRAT (ArechClient2) Variant Hidden Inside Legitimate Italian Digital-Audio Software via…high
- Multi-Stage Abuse of Legitimate Remote Access Tools (ConnectWise, N-Able, SimpleHelp, Datto RMM, GoTo) by…high
- Attackers Manipulate AI Chatbots (ChatGPT, Gemini, Copilot, AI Overviews) via SEO/Content Poisoning for Mass…high
- ShinyHunters Claims FBI Breach via Unpatched Oracle PeopleSoft Zero-Day, Threatens 2-3TB of PII/PHI Leakcritical
- Large-Scale Azure-Hosted Tech Support Scam Campaign Targets Japan (13.38M Emails, 240K+ Relay IPs, 33K+…high
- ClearFake Drive-By Cluster Fuels CastleLoader Paste-and-Run Delivery of NetSupport RAT, CastleRAT, and a…high
- North Korean WaterPlum (Contagious Interview) Hackers Target IT Professionals with BeaverTail…high
- CISA Warns of Active Exploitation of Critical ConnectWise ScreenConnect Flaw (CVE-2026-84869, CVSS 9.9)critical
- Team Cymru Infrastructure Analysis: Seven Active Ransomware Gangs (Akira, DragonForce, Clop, MedusaLocker…high
- Attacker Maintains Root-Level MeshCentral Backdoor Inside Thai ISP 3BB, Targets RADIUS Subscriber-Credential…high
- ScreenConnect Backdoor Delivered via SSA-Impersonation Phishing Luremedium
- Platform-Aware Phishing Kits Fingerprint Devices to Deliver OS-Specific RATs and Credential Harvestershigh
- Browser-in-the-Browser Phishing Campaign Abuses ScreenConnect RMM to Gain Remote Accesshigh
- CVE-2026-86218 — Unauthenticated Pre-Auth Remote Code Execution in N-able N-central (Active Exploitation…critical
- Hyadina Rebrands Beast Ransomware as 'GodDamn' and Uses PoisonX Signed Kernel Driver to Disable Endpoint…critical
- Global Credential-Stealing Phishing Campaign Abusing Trusted Google Services as Redirect Infrastructurehigh
- Rhysida Ransomware Campaign Targeting German Public Administration (Stuttgart and Berlin, 2026)critical
- StyleSmuggler — Magento Open Source and Adobe Commerce Unauthenticated RCE 0-Day Under Active Exploitationcritical
Detection coverage
Threadlinqs maintains 526 detection rules mapped to T1219 (SPL 179, KQL 184, Sigma 163). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1219.001 IDE Tunneling — 1 tracked threat
- T1219.002 Remote Desktop Software — 5 tracked threats
- T1219.003 Remote Access Hardware — 0 tracked threats