Threat reportMalwareTL-2026-1820

Evolution of Remote Access Tool (RAT/RMM) Abuse: Multi-Stage Chaining of ConnectWise, GoTo, Datto, SimpleHelp, N-able, and Heartbeat RM

mediumACTIVE

Evolution of Remote Access Tool (RAT/RMM) Abuse (TL-2026-1820), also tracked as Multi-Stage RAT/RMM Chaining, is a medium-severity malware campaign, first published 2026-08-02. It has no confirmed attribution, affects ConnectWise ConnectWise ScreenConnect (ConnectWise RAT/Control), maps to 24 MITRE ATT&CK techniques (T1005, T1016, T1027.002), and is covered by 9 detection rules and 32 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
0None referenced
Techniques
24MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
32Indicators of compromise

Key facts for TL-2026-1820

Threat ID
TL-2026-1820
Also known as
Multi-Stage RAT/RMM Chaining, Daisy-Chained RMM Abuse
Severity
MEDIUM
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
financial services, real estate and title services, professional services, general enterprise
Target regions
united states of america, North America
Detection rules
9
Indicators of compromise
32

Malware and tooling in Evolution of Remote Access Tool (RAT/RMM) Abuse

Malware and tooling: ConnectWise ScreenConnect (ConnectWise RAT), Datto RMM (CentraStage), GoTo RAT (LogMeIn Resolve / GoTo Resolve), HeartCrypt (Packer-as-a-Service), HeartbeatRM, N-able RMM, SimpleHelp RAT, Sordum Hide From Uninstall List

How Evolution of Remote Access Tool (RAT/RMM) Abuse works

Cofense documents a shift from single-stage RAT deployment to multi-stage phishing campaigns that chain legitimate remote-access/RMM tools (ConnectWise, GoTo, Datto, SimpleHelp, N-able, Heartbeat RM) together for redundant C2, using Sordum's 'Hide From Uninstall List' utility to conceal the installed agents from Windows Add/Remove Programs and evade IT remediation.

Across four Active Threat Reports (ATR 409595, 409165, 408664, 410324) published between January 2025 and March 2026, Cofense observed a consistent evolution in how threat actors weaponize legitimate remote-access and remote-monitoring-and-management (RMM) software. Rather than deploying a single RAT, phishing emails now deliver an initial RAT/RMM installer that, once executed, silently downloads and installs a second, distinct RAT/RMM tool to serve as the actual command-and-control channel — giving the operator redundant, tool-diverse access that survives detection or removal of any one agent. ATR 409595 used Adobe Cloud software-update spoofing to deliver GoTo RAT (LogMeIn Resolve/GoTo Resolve), which then pulled down ConnectWise RAT. ATR 409165 used title-company 'signed documents ready to view' spoofing to deliver Datto RMM, chaining to ConnectWise RAT. ATR 408664 used an event-invitation lure to deliver SimpleHelp RAT, again chaining to ConnectWise RAT. ATR 410324 used a generic document-notification spoof to deliver ConnectWise RAT as the first stage, which chained to Heartbeat RM plus a second, independent ConnectWise RAT instance for redundancy.

A second defining feature of the trend is post-install concealment: attackers deploy the Sordum.org 'Hide From Uninstall List' portable utility (a legitimate freeware tool intended to declutter Add/Remove Programs) to strip the installed RAT/RMM entries from the Windows uninstall list, making the unauthorized software invisible to IT staff and defenders performing manual or asset-inventory-driven remediation.

This pattern is not isolated to the four Cofense ATRs. Correlated reporting from Sophos (tracked as activity cluster STAC6405), Huntress, and Microsoft describes the same tool-chaining tradecraft at wider scale: Sophos observed LogMeIn Resolve delivered via 'Punchbowl'-branded invitation-lure phishing chained, within an hour, to a pre-existing ScreenConnect installation to pull a HeartCrypt-packed infostealer or a JWrapper-based Java RAT, affecting 80+ mostly US organizations from April 2025 (peaking October-November 2025). Huntress independently reported RMM abuse reaching 24% of observed incidents (a 277% year-over-year increase) driven by daisy-chained RMM deployments (ScreenConnect, Action1, SimpleHelp, GoTo Resolve, Datto CentraStage) via MSI installers and WScript chains in December 2025-January 2026, and Microsoft/security researchers reported tax-season W-2/Form 1099 phishing lures delivering ScreenConnect, SimpleHelp, and Datto as final payloads in early 2026. None of these correlated reports are confirmed as the same intrusion set as the four Cofense ATRs; they are recorded here as adjacent evidence of the same TTP because all abuse the same class of enterprise-legitimate RMM software as a first-class attack tool, chained in pairs, to survive single-tool detection and removal.

Because every tool involved (ConnectWise, GoTo, Datto, SimpleHelp, N-able, Heartbeat RM, ScreenConnect, Action1) is dual-use commercial software commonly allow-listed by application-control policy, this technique is inherently evasive: it requires no exploit, no CVE, and often no malware in the traditional sense — the payload is the legitimate remote-access capability itself, obtained via a free trial, portable/self-contained executable, or a compromised/spoofed sender account.

MITRE ATT&CK techniques used in TL-2026-1820

Collection

T1005 Data from Local System; T1119 Automated Collection

Discovery

T1016 System Network Configuration Discovery; T1082 System Information Discovery; T1518.001 Security Software Discovery

Defense Evasion

T1027.002 Software Packing; T1027.004 Compile After Delivery; T1036 Masquerading; T1055 Process Injection; T1497.003 Time Based Checks; T1564 Hide Artifacts

Command and Control

T1071.001 Web Protocols; T1090 Proxy; T1105 Ingress Tool Transfer; T1219 Remote Access Tools; T1573 Encrypted Channel

defense-impairment

T1112 Modify Registry

Execution

T1204.002 Malicious File

Persistence

T1543.003 Windows Service

Credential Access

T1555.003 Credentials from Web Browsers

Initial Access

T1566.002 Spearphishing Link

Resource Development

T1583.001 Domains; T1586.002 Email Accounts; T1608.001 Upload Malware

Affected products and versions in Evolution of Remote Access Tool (RAT/RMM) Abuse

  • ConnectWise — ConnectWise ScreenConnect (ConnectWise RAT/Control)
    Vulnerable versions: any version reachable via unauthorized/rogue portable installation, free trial, or spoofed sender
    Fixed in: N/A - abuse of legitimate software feature, not a version-specific vulnerability
  • GoTo (LogMeIn) — GoTo Resolve / LogMeIn Resolve
    Vulnerable versions: any version reachable via unauthorized/rogue installation
    Fixed in: N/A - abuse of legitimate software feature
  • Datto (a Kaseya company) — Datto RMM (CentraStage)
    Vulnerable versions: any version reachable via unauthorized/rogue installation
    Fixed in: N/A - abuse of legitimate software feature
  • SimpleHelp — SimpleHelp RMM/Remote Access
    Vulnerable versions: any version reachable via unauthorized/rogue installation
    Fixed in: N/A - abuse of legitimate software feature; note a separate vulnerability chain (CVE-2024-57726/57727/57728) affects unpatched SimpleHelp ≤5.5.7, tracked independently under CISA AA25-163A
  • N-able — N-able RMM
    Vulnerable versions: any version reachable via unauthorized/rogue installation
    Fixed in: N/A - abuse of legitimate software feature
  • Heartbeat RM — Heartbeat Remote Monitoring
    Vulnerable versions: any version reachable via unauthorized/rogue installation
    Fixed in: N/A - abuse of legitimate software feature

Remediation for Evolution of Remote Access Tool (RAT/RMM) Abuse

Patches

  • Not applicable — this is abuse of legitimate, licensed remote-access software features via social engineering, not a software vulnerability; no CVE is associated with this campaign
  • Independently ensure any SimpleHelp RMM deployments are patched against the separately-tracked CVE-2024-57726/CVE-2024-57727/CVE-2024-57728 (see CISA AA25-163A) — that is a distinct exploitation vector against the same product family named in this campaign

Immediate actions

  • Add ConnectWise/ScreenConnect, GoTo Resolve/LogMeIn Resolve, Datto RMM, SimpleHelp, N-able, and Heartbeat RM installers to a default-deny EDR/application-control allowlist unless the specific instance is IT-deployed and licensed
  • Hunt for the Sordum.org 'Hide From Uninstall List' utility and for RMM services present in Windows service listings / running-process inventory but absent from HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall registry keys — that mismatch is a strong compromise indicator
  • Block the known STAC6405-cluster distribution/relay infrastructure at the email and network perimeter: mastorpasstop[.]top, evitereview[.]de, evitesecured[.]top, relay.aceheritagehouse[.]top (TCP/8041), 45.56.162.138
  • Quarantine and investigate any host running ScreenConnect, GoTo Resolve, Datto RMM, SimpleHelp, N-able, or Heartbeat RM that was not provisioned through the organization's IT/MSP deployment process
  • Alert on portable/self-contained RMM executables launched from user-writable paths (Downloads, Temp, %APPDATA%) rather than an administrative software-deployment channel

Workarounds

  • Restrict outbound connectivity to RMM vendor cloud infrastructure to the specific tenant/region endpoints your organization actually uses; block all other RMM vendor cloud ranges by default
  • Enable Windows Defender Application Control (WDAC) or AppLocker rules scoped to approved RMM agent publisher certificates and known-good install paths
  • Require a documented change-ticket / MFA step-up confirmation before any new RMM agent is permitted to register against internal endpoints

Longer-term hardening

  • Implement strict RMM allow-listing keyed on publisher certificate + expected tenant/account ID, rejecting free-trial or unrecognized-tenant instances of any RMM client
  • Deploy phishing-resistant email security with link/attachment sandboxing tuned to invitation/RSVP, title-company document-notification, tax-form (W-2/1099), Adobe-update, and cloud-file-share lure themes
  • Build detections around dual RMM installation events on the same host within a short time window (first-stage-to-second-stage chaining) rather than relying on single-tool signatures
  • Correlate Windows service creation (T1543.003) with newly-installed RMM binaries to catch JWrapper/Java-based or portable-agent persistence
  • Run recurring security-awareness training emphasizing that legitimate-looking RMM/remote-support installers can be malicious even when digitally signed by the real vendor

Timeline of Evolution of Remote Access Tool (RAT/RMM) Abuse

  • Sophos MDR records the earliest observed activity in the STAC6405 cluster: LogMeIn Resolve (GoTo RAT) delivered via phishing and chained to a pre-existing ScreenConnect installation — the earliest documented instance of the RMM daisy-chaining pattern later synthesized by Cofense (month-level precision per source).
  • CISA publishes advisory AA25-163A on ransomware actors exploiting unpatched SimpleHelp RMM (CVE-2024-57726/57727/57728) to compromise a utility billing software provider's downstream customers — a distinct exploitation vector against one of the six RMM products named in this campaign's title.
  • STAC6405 cluster activity peaks (October-November 2025): 'Punchbowl'-branded invitation-lure phishing delivers LogMeIn Resolve to 80+ predominantly US organizations, with attackers pivoting to a pre-existing ScreenConnect install for second-stage payload delivery within roughly an hour of initial compromise.
  • Huntress reports RMM abuse reaching 24% of observed incidents (277% year-over-year increase), documenting daisy-chained RMM deployments (ScreenConnect, Action1, SimpleHelp, GoTo Resolve, Datto CentraStage) via MSI installers and WScript-based chains through January 2026.
  • Microsoft and other researchers report tax-season phishing (W-2 and Form 1099 lures) delivering ScreenConnect, SimpleHelp, and Datto as final RMM payloads.
  • The Hacker News reports on the Sophos-tracked STAC6405 campaign hitting 80+ organizations via LogMeIn Resolve/SimpleHelp and ScreenConnect RMM chaining, corroborating the multi-tool-chaining pattern at scale.
  • Cofense publishes 'The Evolution of Remote Access Tool Abuse,' synthesizing the four ATRs into a documented trend of multi-stage RAT/RMM chaining plus use of the Sordum.org 'Hide From Uninstall List' utility to conceal installed RAT/RMM software from the Windows Add/Remove Programs list.
  • Cofense ATR 410324: document-notification-spoofing phishing email delivers ConnectWise RAT as the first-stage tool, chaining to Heartbeat RM plus a second, independent ConnectWise RAT instance for redundant second-stage C2.
  • Cofense ATR 408664: event-invitation-themed phishing email delivers SimpleHelp RAT as the first-stage tool, chaining to ConnectWise RAT for second-stage C2.
  • Cofense ATR 409165: title-company 'signed documents ready to view' spoofing email delivers Datto RMM as the first-stage tool, chaining to ConnectWise RAT for second-stage C2.
  • Cofense ATR 409595: Adobe Cloud software-update-spoofing phishing email delivers GoTo RAT (LogMeIn Resolve/GoTo Resolve) as the first-stage RMM tool, which downloads ConnectWise RAT as the second-stage C2 channel.

Sources cited for Evolution of Remote Access Tool (RAT/RMM) Abuse

Detection coverage for TL-2026-1820

As of 2026-08-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1820 across Splunk SPL, Microsoft KQL and Sigma, covering 32 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
32 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats