# T1219 Remote Access Tools

> As of 2026-10-05, T1219 (Remote Access Tools) appears in 272 tracked threats, first reported 2026-01-01 and most recently 2026-10-03, with linked actors including MuddyWater, Akira, Contagious Interview; it most often appears alongside T1027 (Obfuscated Files or Information).

- **Tracked threats:** 272 (69 critical, 178 high, 25 medium)
- **First seen:** 2026-01-01
- **Last seen:** 2026-10-03
- **Threat actors:** 93
- **Detection rules:** 526 (counts only; Blue tier and above)

## Key facts

- **ID:** T1219
- **Framework:** MITRE ATT&CK
- **Tactics:** Command and Control
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1219/

## Activity timeline

T1219 first appeared in tracked threats on 2026-01-01 and was most recently reported on 2026-10-03. The busiest month was 2026-07 with 100 reports, and 272 of the 272 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1219 Remote Access Tools is catalogued by MITRE ATT&CK under the Command and Control tactic in the Enterprise matrix. Threadlinqs maps 272 of 2623 tracked threats (10.4%) to it; by severity that is 69 critical, 178 high, 25 medium.

Threats that use T1219 most often also use [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (143 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (129 threats), [T1685 Disable or Modify Tools](https://intel.threadlinqs.com/technique/T1685) (128 threats), [T1036 Masquerading](https://intel.threadlinqs.com/technique/T1036) (126 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (112 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

93 tracked threat actors appear in the threats that use T1219; the most frequent are [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) (8), [Akira](https://intel.threadlinqs.com/actor/Akira) (6), [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) (6), [Storm-1567](https://intel.threadlinqs.com/actor/Storm-1567) (6), [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) (5).

## Mitigations

MITRE ATT&CK lists 5 mitigations for T1219.

- [M1031 Network Intrusion Prevention](https://attack.mitre.org/mitigations/M1031/)
- [M1034 Limit Hardware Installation](https://attack.mitre.org/mitigations/M1034/)
- [M1037 Filter Network Traffic](https://attack.mitre.org/mitigations/M1037/)
- [M1038 Execution Prevention](https://attack.mitre.org/mitigations/M1038/)
- [M1042 Disable or Remove Feature or Program](https://attack.mitre.org/mitigations/M1042/)

## Data sources

Telemetry that can reveal T1219, per MITRE ATT&CK.

- Drive — Drive Creation
- Network Traffic — Network Connection Creation, Network Traffic Content, Network Traffic Flow
- Process — Process Creation

## Threat actors using it

- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 8
- [Akira](https://intel.threadlinqs.com/actor/Akira) — 6
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 6
- [Storm-1567](https://intel.threadlinqs.com/actor/Storm-1567) — 6
- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 5
- [Chaos](https://intel.threadlinqs.com/actor/Chaos) — 4
- [Contagious Interview - G1052](https://intel.threadlinqs.com/actor/Contagious%20Interview%20-%20G1052) — 4
- [Luna Moth](https://intel.threadlinqs.com/actor/Luna%20Moth) — 4
- [Silent Ransom Group](https://intel.threadlinqs.com/actor/Silent%20Ransom%20Group) — 4
- [UNC6240](https://intel.threadlinqs.com/actor/UNC6240) — 4
- [WageMole](https://intel.threadlinqs.com/actor/WageMole) — 4
- [ALPHV](https://intel.threadlinqs.com/actor/ALPHV) — 3

## Tracked threats

The 30 most recent of 272 tracked threats that use T1219.

- [The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira…](https://intel.threadlinqs.com/threat/TL-2026-2852) — high — 2026-10-03
- [Multiple High-Severity Vulnerabilities in TeamViewer Client (CVE-2026-92370, CVE-2026-92368, CVE-2026-92369…](https://intel.threadlinqs.com/threat/TL-2026-2905) — high — 2026-10-02
- [GTIG: AI-Era Vulnerability Discovery and Exploitation Surge — In-the-Wild Exploitation of BeyondTrust…](https://intel.threadlinqs.com/threat/TL-2026-2818) — critical — 2026-09-30
- [CSuite Phishing Operation Steals Microsoft 365 Sessions via Device-Code Phishing and Deploys…](https://intel.threadlinqs.com/threat/TL-2026-2802) — high — 2026-09-30
- [Phishing Campaigns Abuse RMM Tools (MSP360, ScreenConnect) for Persistent Access](https://intel.threadlinqs.com/threat/TL-2026-2788) — high — 2026-09-29
- [North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum Transactions (HashHiding) for Covert C2 Signaling](https://intel.threadlinqs.com/threat/TL-2026-2782) — high — 2026-09-29
- [ShinyHunters Claims Breach of FBI Jobs Portal (fbijobs.gov) via Alleged Oracle PeopleSoft Zero-Day, Exposing…](https://intel.threadlinqs.com/threat/TL-2026-2760) — high — 2026-09-28
- [Microsoft Tracks Storm-2570 Ransomware Affiliate Behind Qilin, DragonForce, Anubis, and BERT Deployments](https://intel.threadlinqs.com/threat/TL-2026-2729) — high — 2026-09-27
- [OS-Aware Phishing Kit Fans Fake iCloud Alert into ScreenConnect RMM, Apple ID, and M365 AiTM Harvesters](https://intel.threadlinqs.com/threat/TL-2026-2704) — high — 2026-09-27
- [Sauron Loader: New DLL Side-Loading Malware-as-a-Service Deployed Against German Organizations via ClickFix…](https://intel.threadlinqs.com/threat/TL-2026-2685) — high — 2026-09-27
- [Kothamine RAT Abuses Tailscale's Tailcat for Encrypted C2, Distributed via Malicious npm Packages](https://intel.threadlinqs.com/threat/TL-2026-2665) — high — 2026-09-26
- [Malicious Google Ads campaign delivers browser-locking fake tech support scareware to Windows and Mac users](https://intel.threadlinqs.com/threat/TL-2026-2651) — high — 2026-09-25
- [SectopRAT (ArechClient2) Variant Hidden Inside Legitimate Italian Digital-Audio Software via…](https://intel.threadlinqs.com/threat/TL-2026-2646) — high — 2026-09-25
- [Multi-Stage Abuse of Legitimate Remote Access Tools (ConnectWise, N-Able, SimpleHelp, Datto RMM, GoTo) by…](https://intel.threadlinqs.com/threat/TL-2026-2645) — high — 2026-09-25
- [Attackers Manipulate AI Chatbots (ChatGPT, Gemini, Copilot, AI Overviews) via SEO/Content Poisoning for Mass…](https://intel.threadlinqs.com/threat/TL-2026-2631) — high — 2026-09-23
- [ShinyHunters Claims FBI Breach via Unpatched Oracle PeopleSoft Zero-Day, Threatens 2-3TB of PII/PHI Leak](https://intel.threadlinqs.com/threat/TL-2026-2620) — critical — 2026-09-22
- [Large-Scale Azure-Hosted Tech Support Scam Campaign Targets Japan (13.38M Emails, 240K+ Relay IPs, 33K+…](https://intel.threadlinqs.com/threat/TL-2026-2595) — high — 2026-09-21
- [ClearFake Drive-By Cluster Fuels CastleLoader Paste-and-Run Delivery of NetSupport RAT, CastleRAT, and a…](https://intel.threadlinqs.com/threat/TL-2026-2589) — high — 2026-09-20
- [North Korean WaterPlum (Contagious Interview) Hackers Target IT Professionals with BeaverTail…](https://intel.threadlinqs.com/threat/TL-2026-2577) — high — 2026-09-19
- [CISA Warns of Active Exploitation of Critical ConnectWise ScreenConnect Flaw (CVE-2026-84869, CVSS 9.9)](https://intel.threadlinqs.com/threat/TL-2026-2533) — critical — 2026-09-16
- [Team Cymru Infrastructure Analysis: Seven Active Ransomware Gangs (Akira, DragonForce, Clop, MedusaLocker…](https://intel.threadlinqs.com/threat/TL-2026-2517) — high — 2026-09-15
- [Attacker Maintains Root-Level MeshCentral Backdoor Inside Thai ISP 3BB, Targets RADIUS Subscriber-Credential…](https://intel.threadlinqs.com/threat/TL-2026-2514) — high — 2026-09-15
- [ScreenConnect Backdoor Delivered via SSA-Impersonation Phishing Lure](https://intel.threadlinqs.com/threat/TL-2026-2594) — medium — 2026-09-14
- [Platform-Aware Phishing Kits Fingerprint Devices to Deliver OS-Specific RATs and Credential Harvesters](https://intel.threadlinqs.com/threat/TL-2026-2452) — high — 2026-09-11
- [Browser-in-the-Browser Phishing Campaign Abuses ScreenConnect RMM to Gain Remote Access](https://intel.threadlinqs.com/threat/TL-2026-2453) — high — 2026-09-09
- [CVE-2026-86218 — Unauthenticated Pre-Auth Remote Code Execution in N-able N-central (Active Exploitation…](https://intel.threadlinqs.com/threat/TL-2026-2415) — critical — 2026-09-09
- [Hyadina Rebrands Beast Ransomware as 'GodDamn' and Uses PoisonX Signed Kernel Driver to Disable Endpoint…](https://intel.threadlinqs.com/threat/TL-2026-2409) — critical — 2026-09-08
- [Global Credential-Stealing Phishing Campaign Abusing Trusted Google Services as Redirect Infrastructure](https://intel.threadlinqs.com/threat/TL-2026-2372) — high — 2026-09-07
- [Rhysida Ransomware Campaign Targeting German Public Administration (Stuttgart and Berlin, 2026)](https://intel.threadlinqs.com/threat/TL-2026-2357) — critical — 2026-09-06
- [StyleSmuggler — Magento Open Source and Adobe Commerce Unauthenticated RCE 0-Day Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2356) — critical — 2026-09-06

## Related CVEs

CVEs referenced by the tracked threats that use T1219, most frequent first.

- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2026-1731](https://intel.threadlinqs.com/cve/CVE-2026-1731)
- [CVE-2024-1709](https://intel.threadlinqs.com/cve/CVE-2024-1709)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2021-22681](https://intel.threadlinqs.com/cve/CVE-2021-22681)
- [CVE-2023-3519](https://intel.threadlinqs.com/cve/CVE-2023-3519)
- [CVE-2023-4966](https://intel.threadlinqs.com/cve/CVE-2023-4966)
- [CVE-2024-1708](https://intel.threadlinqs.com/cve/CVE-2024-1708)
- [CVE-2024-37085](https://intel.threadlinqs.com/cve/CVE-2024-37085)
- [CVE-2024-40766](https://intel.threadlinqs.com/cve/CVE-2024-40766)
- [CVE-2024-53704](https://intel.threadlinqs.com/cve/CVE-2024-53704)
- [CVE-2024-57727](https://intel.threadlinqs.com/cve/CVE-2024-57727)
- [CVE-2025-5777](https://intel.threadlinqs.com/cve/CVE-2025-5777)
- [CVE-2026-45659](https://intel.threadlinqs.com/cve/CVE-2026-45659)
- [CVE-2026-56164](https://intel.threadlinqs.com/cve/CVE-2026-56164)
- [CVE-2021-42278](https://intel.threadlinqs.com/cve/CVE-2021-42278)
- [CVE-2021-42287](https://intel.threadlinqs.com/cve/CVE-2021-42287)
- [CVE-2022-20775](https://intel.threadlinqs.com/cve/CVE-2022-20775)
- [CVE-2023-27350](https://intel.threadlinqs.com/cve/CVE-2023-27350)
- [CVE-2024-27198](https://intel.threadlinqs.com/cve/CVE-2024-27198)
- [CVE-2024-40711](https://intel.threadlinqs.com/cve/CVE-2024-40711)
- [CVE-2024-57726](https://intel.threadlinqs.com/cve/CVE-2024-57726)
- [CVE-2024-57728](https://intel.threadlinqs.com/cve/CVE-2024-57728)
- [CVE-2025-26125](https://intel.threadlinqs.com/cve/CVE-2025-26125)
- [CVE-2025-32433](https://intel.threadlinqs.com/cve/CVE-2025-32433)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-9491](https://intel.threadlinqs.com/cve/CVE-2025-9491)
- [CVE-2026-0257](https://intel.threadlinqs.com/cve/CVE-2026-0257)

## Detection coverage

Threadlinqs maintains 526 detection rules mapped to T1219 (SPL 179, KQL 184, Sigma 163). Rule content is available to Blue tier accounts and above; this page shows counts only.

526 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- T1219.001 IDE Tunneling — 1 tracked threat
- T1219.002 Remote Desktop Software — 5 tracked threats
- T1219.003 Remote Access Hardware — 0 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1219
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
