Evolution of Remote Access Tool (RAT/RMM) Abuse: Multi-Stage Chaining of ConnectWise, GoTo, Datto, SimpleHelp, N-able, and Heartbeat RM — Threadlinqs Intelligence
As of 2026-08-02, Evolution of Remote Access Tool (RAT/RMM) Abuse: Multi-Stage Chaining of ConnectWise, GoTo, Datto, SimpleHelp, N-able, and Heartbeat RM is a medium-severity malware threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 32 indicators of compromise.
Threat ID: TL-2026-1820 · Severity: MEDIUM · Status: ACTIVE · Category: MALWARE
Cofense documents a shift from single-stage RAT deployment to multi-stage phishing campaigns that chain legitimate remote-access/RMM tools (ConnectWise, GoTo, Datto, SimpleHelp, N-able, Heartbeat RM)
Across four Active Threat Reports (ATR 409595, 409165, 408664, 410324) published between January 2025 and March 2026, Cofense observed a consistent evolution in how threat actors weaponize legitimate remote-access and remote-monitoring-and-management (RMM) software. Rather than deploying a single RAT, phishing emails now deliver an initial RAT/RMM installer that, once executed, silently downloads and installs a second, distinct RAT/RMM tool to serve as the actual command-and-control channel — giving the operator redundant, tool-diverse access that survives detection or removal of any one agent. ATR 409595 used Adobe Cloud software-update spoofing to deliver GoTo RAT (LogMeIn Resolve/GoTo Resolve), which then pulled down ConnectWise RAT. ATR 409165 used title-company 'signed documents ready to view' spoofing to deliver Datto RMM, chaining to ConnectWise RAT. ATR 408664 used an event-invitation lure to deliver SimpleHelp RAT, again chaining to ConnectWise RAT. ATR 410324 used a generic document-notification spoof to deliver ConnectWise RAT as the first stage, which chained to Heartbeat RM plus a second, independent ConnectWise RAT instance for redundancy.
A second defining feature of the trend is post-install concealment: attackers deploy the Sordum.org 'Hide From Uninstall List' portable utility (a legitimate freeware tool intended to declutter Add/Remove Programs) to strip the installed RAT/RMM entries from the Windows uninstall list, making the unauthorized software invisible to IT staff and defenders performing manual or asset-inventory-driven remediation.
This pattern is not isolated to the four Cofense ATRs. Correlated reporting from Sophos (tracked as activity cluster STAC6405), Huntress, and Microsoft describes the same tool-chaining tradecraft at wider scale: Sophos observed LogMeIn Resolve delivered via 'Punchbowl'-branded invitation-lure phishing chained, within an hour, to a pre-existing ScreenConnect installation to pull a HeartCrypt-packed infostealer or a JWrapper-based Java RAT, affecting 80+ mostly US organizations from April 2025 (peaking October-November 2025). Huntress independently reported RMM abuse reaching 24% of observed incidents (a 277% year-over-year increase) driven by daisy-chained RMM deployments (ScreenConnect, Action1, SimpleHelp, GoTo Resolve, Datto CentraStage) via MSI installers and WScript chains in December 2025-January 2026, and Microsoft/security researchers reported tax-season W-2/Form 1099 phishing lures delivering ScreenConnect, SimpleHelp, and Datto as final payloads in early 2026. None of these correlated reports are confirmed as the same intrusion set as the four Cofense ATRs; they are recorded here as adjacent evidence of the same TTP because all abuse the same class of enterprise-legitimate RMM software as a first-class attack tool, chained in pairs, to survive single-tool detection and removal.
Because every tool involved (ConnectWise, GoTo, Datto, SimpleHelp, N-able, Heartbeat RM, ScreenConnect, Action1) is dual-use commercial software commonly allow-listed by application-control policy, this technique is inherently evasive: it requires no exploit, no CVE, and often no malware in the traditional sense — the payload is the legitimate remote-access capability itself, obtained via a free trial, portable/self-contained executable, or a compromised/spoofed sender account.
Target sectors: financial services, real estate and title services, professional services, general enterprise
Target regions: united states of america, North America
Detections & IOCs
As of 2026-08-08, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 32 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, MEDIUM, threat intelligence, cybersecurity, T1583.001, T1586.002, T1608.001, T1566.002, T1204.002, T1543.003, T1036, T1027.002, T1027.004, T1055