Threat reportMalwareTL-2026-1820
Evolution of Remote Access Tool (RAT/RMM) Abuse: Multi-Stage Chaining of ConnectWise, GoTo, Datto, SimpleHelp, N-able, and Heartbeat RM
Evolution of Remote Access Tool (RAT/RMM) Abuse (TL-2026-1820), also tracked as Multi-Stage RAT/RMM Chaining, is a medium-severity malware campaign, first published 2026-08-02. It has no confirmed attribution, affects ConnectWise ConnectWise ScreenConnect (ConnectWise RAT/Control), maps to 24 MITRE ATT&CK techniques (T1005, T1016, T1027.002), and is covered by 9 detection rules and 32 indicators of compromise.
- Severity
- MEDIUMAssessed severity
- CVEs
- 0None referenced
- Techniques
- 24MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 32Indicators of compromise
Key facts for TL-2026-1820
- Threat ID
- TL-2026-1820
- Also known as
- Multi-Stage RAT/RMM Chaining, Daisy-Chained RMM Abuse
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- financial services, real estate and title services, professional services, general enterprise
- Target regions
- united states of america, North America
- Detection rules
- 9
- Indicators of compromise
- 32
Malware and tooling in Evolution of Remote Access Tool (RAT/RMM) Abuse
Malware and tooling: ConnectWise ScreenConnect (ConnectWise RAT), Datto RMM (CentraStage), GoTo RAT (LogMeIn Resolve / GoTo Resolve), HeartCrypt (Packer-as-a-Service), HeartbeatRM, N-able RMM, SimpleHelp RAT, Sordum Hide From Uninstall List
How Evolution of Remote Access Tool (RAT/RMM) Abuse works
Cofense documents a shift from single-stage RAT deployment to multi-stage phishing campaigns that chain legitimate remote-access/RMM tools (ConnectWise, GoTo, Datto, SimpleHelp, N-able, Heartbeat RM) together for redundant C2, using Sordum's 'Hide From Uninstall List' utility to conceal the installed agents from Windows Add/Remove Programs and evade IT remediation.
Across four Active Threat Reports (ATR 409595, 409165, 408664, 410324) published between January 2025 and March 2026, Cofense observed a consistent evolution in how threat actors weaponize legitimate remote-access and remote-monitoring-and-management (RMM) software. Rather than deploying a single RAT, phishing emails now deliver an initial RAT/RMM installer that, once executed, silently downloads and installs a second, distinct RAT/RMM tool to serve as the actual command-and-control channel — giving the operator redundant, tool-diverse access that survives detection or removal of any one agent. ATR 409595 used Adobe Cloud software-update spoofing to deliver GoTo RAT (LogMeIn Resolve/GoTo Resolve), which then pulled down ConnectWise RAT. ATR 409165 used title-company 'signed documents ready to view' spoofing to deliver Datto RMM, chaining to ConnectWise RAT. ATR 408664 used an event-invitation lure to deliver SimpleHelp RAT, again chaining to ConnectWise RAT. ATR 410324 used a generic document-notification spoof to deliver ConnectWise RAT as the first stage, which chained to Heartbeat RM plus a second, independent ConnectWise RAT instance for redundancy.
A second defining feature of the trend is post-install concealment: attackers deploy the Sordum.org 'Hide From Uninstall List' portable utility (a legitimate freeware tool intended to declutter Add/Remove Programs) to strip the installed RAT/RMM entries from the Windows uninstall list, making the unauthorized software invisible to IT staff and defenders performing manual or asset-inventory-driven remediation.
This pattern is not isolated to the four Cofense ATRs. Correlated reporting from Sophos (tracked as activity cluster STAC6405), Huntress, and Microsoft describes the same tool-chaining tradecraft at wider scale: Sophos observed LogMeIn Resolve delivered via 'Punchbowl'-branded invitation-lure phishing chained, within an hour, to a pre-existing ScreenConnect installation to pull a HeartCrypt-packed infostealer or a JWrapper-based Java RAT, affecting 80+ mostly US organizations from April 2025 (peaking October-November 2025). Huntress independently reported RMM abuse reaching 24% of observed incidents (a 277% year-over-year increase) driven by daisy-chained RMM deployments (ScreenConnect, Action1, SimpleHelp, GoTo Resolve, Datto CentraStage) via MSI installers and WScript chains in December 2025-January 2026, and Microsoft/security researchers reported tax-season W-2/Form 1099 phishing lures delivering ScreenConnect, SimpleHelp, and Datto as final payloads in early 2026. None of these correlated reports are confirmed as the same intrusion set as the four Cofense ATRs; they are recorded here as adjacent evidence of the same TTP because all abuse the same class of enterprise-legitimate RMM software as a first-class attack tool, chained in pairs, to survive single-tool detection and removal.
Because every tool involved (ConnectWise, GoTo, Datto, SimpleHelp, N-able, Heartbeat RM, ScreenConnect, Action1) is dual-use commercial software commonly allow-listed by application-control policy, this technique is inherently evasive: it requires no exploit, no CVE, and often no malware in the traditional sense — the payload is the legitimate remote-access capability itself, obtained via a free trial, portable/self-contained executable, or a compromised/spoofed sender account.
MITRE ATT&CK techniques used in TL-2026-1820
Collection
T1005 Data from Local System; T1119 Automated Collection
Discovery
T1016 System Network Configuration Discovery; T1082 System Information Discovery; T1518.001 Security Software Discovery
Defense Evasion
T1027.002 Software Packing; T1027.004 Compile After Delivery; T1036 Masquerading; T1055 Process Injection; T1497.003 Time Based Checks; T1564 Hide Artifacts
Command and Control
T1071.001 Web Protocols; T1090 Proxy; T1105 Ingress Tool Transfer; T1219 Remote Access Tools; T1573 Encrypted Channel
defense-impairment
Execution
Persistence
Credential Access
T1555.003 Credentials from Web Browsers
Initial Access
Resource Development
T1583.001 Domains; T1586.002 Email Accounts; T1608.001 Upload Malware
Affected products and versions in Evolution of Remote Access Tool (RAT/RMM) Abuse
- ConnectWise — ConnectWise ScreenConnect (ConnectWise RAT/Control)
Vulnerable versions: any version reachable via unauthorized/rogue portable installation, free trial, or spoofed sender
Fixed in: N/A - abuse of legitimate software feature, not a version-specific vulnerability - GoTo (LogMeIn) — GoTo Resolve / LogMeIn Resolve
Vulnerable versions: any version reachable via unauthorized/rogue installation
Fixed in: N/A - abuse of legitimate software feature - Datto (a Kaseya company) — Datto RMM (CentraStage)
Vulnerable versions: any version reachable via unauthorized/rogue installation
Fixed in: N/A - abuse of legitimate software feature - SimpleHelp — SimpleHelp RMM/Remote Access
Vulnerable versions: any version reachable via unauthorized/rogue installation
Fixed in: N/A - abuse of legitimate software feature; note a separate vulnerability chain (CVE-2024-57726/57727/57728) affects unpatched SimpleHelp ≤5.5.7, tracked independently under CISA AA25-163A - N-able — N-able RMM
Vulnerable versions: any version reachable via unauthorized/rogue installation
Fixed in: N/A - abuse of legitimate software feature - Heartbeat RM — Heartbeat Remote Monitoring
Vulnerable versions: any version reachable via unauthorized/rogue installation
Fixed in: N/A - abuse of legitimate software feature
Remediation for Evolution of Remote Access Tool (RAT/RMM) Abuse
Patches
- Not applicable — this is abuse of legitimate, licensed remote-access software features via social engineering, not a software vulnerability; no CVE is associated with this campaign
- Independently ensure any SimpleHelp RMM deployments are patched against the separately-tracked CVE-2024-57726/CVE-2024-57727/CVE-2024-57728 (see CISA AA25-163A) — that is a distinct exploitation vector against the same product family named in this campaign
Immediate actions
- Add ConnectWise/ScreenConnect, GoTo Resolve/LogMeIn Resolve, Datto RMM, SimpleHelp, N-able, and Heartbeat RM installers to a default-deny EDR/application-control allowlist unless the specific instance is IT-deployed and licensed
- Hunt for the Sordum.org 'Hide From Uninstall List' utility and for RMM services present in Windows service listings / running-process inventory but absent from HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall registry keys — that mismatch is a strong compromise indicator
- Block the known STAC6405-cluster distribution/relay infrastructure at the email and network perimeter: mastorpasstop[.]top, evitereview[.]de, evitesecured[.]top, relay.aceheritagehouse[.]top (TCP/8041), 45.56.162.138
- Quarantine and investigate any host running ScreenConnect, GoTo Resolve, Datto RMM, SimpleHelp, N-able, or Heartbeat RM that was not provisioned through the organization's IT/MSP deployment process
- Alert on portable/self-contained RMM executables launched from user-writable paths (Downloads, Temp, %APPDATA%) rather than an administrative software-deployment channel
Workarounds
- Restrict outbound connectivity to RMM vendor cloud infrastructure to the specific tenant/region endpoints your organization actually uses; block all other RMM vendor cloud ranges by default
- Enable Windows Defender Application Control (WDAC) or AppLocker rules scoped to approved RMM agent publisher certificates and known-good install paths
- Require a documented change-ticket / MFA step-up confirmation before any new RMM agent is permitted to register against internal endpoints
Longer-term hardening
- Implement strict RMM allow-listing keyed on publisher certificate + expected tenant/account ID, rejecting free-trial or unrecognized-tenant instances of any RMM client
- Deploy phishing-resistant email security with link/attachment sandboxing tuned to invitation/RSVP, title-company document-notification, tax-form (W-2/1099), Adobe-update, and cloud-file-share lure themes
- Build detections around dual RMM installation events on the same host within a short time window (first-stage-to-second-stage chaining) rather than relying on single-tool signatures
- Correlate Windows service creation (T1543.003) with newly-installed RMM binaries to catch JWrapper/Java-based or portable-agent persistence
- Run recurring security-awareness training emphasizing that legitimate-looking RMM/remote-support installers can be malicious even when digitally signed by the real vendor
Timeline of Evolution of Remote Access Tool (RAT/RMM) Abuse
- Sophos MDR records the earliest observed activity in the STAC6405 cluster: LogMeIn Resolve (GoTo RAT) delivered via phishing and chained to a pre-existing ScreenConnect installation — the earliest documented instance of the RMM daisy-chaining pattern later synthesized by Cofense (month-level precision per source).
- CISA publishes advisory AA25-163A on ransomware actors exploiting unpatched SimpleHelp RMM (CVE-2024-57726/57727/57728) to compromise a utility billing software provider's downstream customers — a distinct exploitation vector against one of the six RMM products named in this campaign's title.
- STAC6405 cluster activity peaks (October-November 2025): 'Punchbowl'-branded invitation-lure phishing delivers LogMeIn Resolve to 80+ predominantly US organizations, with attackers pivoting to a pre-existing ScreenConnect install for second-stage payload delivery within roughly an hour of initial compromise.
- Huntress reports RMM abuse reaching 24% of observed incidents (277% year-over-year increase), documenting daisy-chained RMM deployments (ScreenConnect, Action1, SimpleHelp, GoTo Resolve, Datto CentraStage) via MSI installers and WScript-based chains through January 2026.
- Microsoft and other researchers report tax-season phishing (W-2 and Form 1099 lures) delivering ScreenConnect, SimpleHelp, and Datto as final RMM payloads.
- The Hacker News reports on the Sophos-tracked STAC6405 campaign hitting 80+ organizations via LogMeIn Resolve/SimpleHelp and ScreenConnect RMM chaining, corroborating the multi-tool-chaining pattern at scale.
- Cofense publishes 'The Evolution of Remote Access Tool Abuse,' synthesizing the four ATRs into a documented trend of multi-stage RAT/RMM chaining plus use of the Sordum.org 'Hide From Uninstall List' utility to conceal installed RAT/RMM software from the Windows Add/Remove Programs list.
- Cofense ATR 410324: document-notification-spoofing phishing email delivers ConnectWise RAT as the first-stage tool, chaining to Heartbeat RM plus a second, independent ConnectWise RAT instance for redundant second-stage C2.
- Cofense ATR 408664: event-invitation-themed phishing email delivers SimpleHelp RAT as the first-stage tool, chaining to ConnectWise RAT for second-stage C2.
- Cofense ATR 409165: title-company 'signed documents ready to view' spoofing email delivers Datto RMM as the first-stage tool, chaining to ConnectWise RAT for second-stage C2.
- Cofense ATR 409595: Adobe Cloud software-update-spoofing phishing email delivers GoTo RAT (LogMeIn Resolve/GoTo Resolve) as the first-stage RMM tool, which downloads ConnectWise RAT as the second-stage C2 channel.
Sources cited for Evolution of Remote Access Tool (RAT/RMM) Abuse
- The Evolution of Remote Access Tool Abuse
- New Weapon of Choice: How Threat Actors Hijack Legitimate Remote Access Tools
- Incident responders, s'il vous plait: Invites lead to odd malware events (STAC6405)
- Phishing Campaign Hits 80+ Orgs Using SimpleHelp and ScreenConnect RMM Tools
- How Threat Actors Abuse Remote Management Tools (Daisy-Chaining Rogue RMM Tools)
- AA25-163A: Ransomware Actors Exploit Unpatched SimpleHelp RMM to Compromise Utility Billing Software Provider
- AA23-025A: Protecting Against Malicious Use of Remote Monitoring and Management Software
- ConnectWise ScreenConnect Tops List of Abused RATs in 2025 Attacks
- Remote Access Software, Technique T1219 - Enterprise | MITRE ATT&CK
- Threat Actors Exploit LogMeIn Resolve, ScreenConnect in Phishing Campaigns
- Sordum - Hide From Uninstall List v1.1
Detection coverage for TL-2026-1820
As of 2026-08-02, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1820 across Splunk SPL, Microsoft KQL and Sigma, covering 32 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.