# Evolution of Remote Access Tool (RAT/RMM) Abuse: Multi-Stage Chaining of ConnectWise, GoTo, Datto, SimpleHelp, N-able, and Heartbeat RM

> Cofense documents a shift from single-stage RAT deployment to multi-stage phishing campaigns that chain legitimate remote-access/RMM tools (ConnectWise, GoTo, Datto, SimpleHelp, N-able, Heartbeat RM) together for redundant C2, using Sordum's 'Hide From Uninstall List' utility to conceal the installed agents from Windows Add/Remove Programs and evade IT remediation.

- **Published:** 2026-08-02T00:00:00Z
- **Last reviewed:** 2026-08-02T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1820
- **ID:** TL-2026-1820
- **Severity:** MEDIUM
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 32 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Across four Active Threat Reports (ATR 409595, 409165, 408664, 410324) published between January 2025 and March 2026, Cofense observed a consistent evolution in how threat actors weaponize legitimate remote-access and remote-monitoring-and-management (RMM) software. Rather than deploying a single RAT, phishing emails now deliver an initial RAT/RMM installer that, once executed, silently downloads and installs a second, distinct RAT/RMM tool to serve as the actual command-and-control channel — giving the operator redundant, tool-diverse access that survives detection or removal of any one agent. ATR 409595 used Adobe Cloud software-update spoofing to deliver GoTo RAT (LogMeIn Resolve/GoTo Resolve), which then pulled down ConnectWise RAT. ATR 409165 used title-company 'signed documents ready to view' spoofing to deliver Datto RMM, chaining to ConnectWise RAT. ATR 408664 used an event-invitation lure to deliver SimpleHelp RAT, again chaining to ConnectWise RAT. ATR 410324 used a generic document-notification spoof to deliver ConnectWise RAT as the first stage, which chained to Heartbeat RM plus a second, independent ConnectWise RAT instance for redundancy.

A second defining feature of the trend is post-install concealment: attackers deploy the Sordum.org 'Hide From Uninstall List' portable utility (a legitimate freeware tool intended to declutter Add/Remove Programs) to strip the installed RAT/RMM entries from the Windows uninstall list, making the unauthorized software invisible to IT staff and defenders performing manual or asset-inventory-driven remediation.

This pattern is not isolated to the four Cofense ATRs. Correlated reporting from Sophos (tracked as activity cluster STAC6405), Huntress, and Microsoft describes the same tool-chaining tradecraft at wider scale: Sophos observed LogMeIn Resolve delivered via 'Punchbowl'-branded invitation-lure phishing chained, within an hour, to a pre-existing ScreenConnect installation to pull a HeartCrypt-packed infostealer or a JWrapper-based Java RAT, affecting 80+ mostly US organizations from April 2025 (peaking October-November 2025). Huntress independently reported RMM abuse reaching 24% of observed incidents (a 277% year-over-year increase) driven by daisy-chained RMM deployments (ScreenConnect, Action1, SimpleHelp, GoTo Resolve, Datto CentraStage) via MSI installers and WScript chains in December 2025-January 2026, and Microsoft/security researchers reported tax-season W-2/Form 1099 phishing lures delivering ScreenConnect, SimpleHelp, and Datto as final payloads in early 2026. None of these correlated reports are confirmed as the same intrusion set as the four Cofense ATRs; they are recorded here as adjacent evidence of the same TTP because all abuse the same class of enterprise-legitimate RMM software as a first-class attack tool, chained in pairs, to survive single-tool detection and removal.

Because every tool involved (ConnectWise, GoTo, Datto, SimpleHelp, N-able, Heartbeat RM, ScreenConnect, Action1) is dual-use commercial software commonly allow-listed by application-control policy, this technique is inherently evasive: it requires no exploit, no CVE, and often no malware in the traditional sense — the payload is the legitimate remote-access capability itself, obtained via a free trial, portable/self-contained executable, or a compromised/spoofed sender account.

## MITRE ATT&CK

- T1583.001 Domains
- T1586.002 Email Accounts
- T1608.001 Upload Malware
- T1566.002 Spearphishing Link
- T1204.002 Malicious File
- T1543.003 Windows Service
- T1036 Masquerading
- T1027.002 Software Packing
- T1027.004 Compile After Delivery
- T1055 Process Injection
- T1497.003 Time Based Checks
- T1112 Modify Registry
- T1564 Hide Artifacts
- T1555.003 Credentials from Web Browsers
- T1518.001 Security Software Discovery
- T1082 System Information Discovery
- T1016 System Network Configuration Discovery
- T1119 Automated Collection
- T1005 Data from Local System
- T1105 Ingress Tool Transfer
- T1219 Remote Access Tools
- T1071.001 Web Protocols
- T1573 Encrypted Channel
- T1090 Proxy

## Sources

- [The Evolution of Remote Access Tool Abuse](https://cofense.com/blog/the-evolution-of-remote-access-tool-abuse)
- [New Weapon of Choice: How Threat Actors Hijack Legitimate Remote Access Tools](https://cofense.com/blog/new-weapon-of-choice-how-threat-actors-hijack-legitimate-remote-access-tools)
- [Incident responders, s'il vous plait: Invites lead to odd malware events (STAC6405)](https://www.sophos.com/en-us/blog/incident-responders-s-il-vous-plait)
- [Phishing Campaign Hits 80+ Orgs Using SimpleHelp and ScreenConnect RMM Tools](https://thehackernews.com/2026/05/phishing-campaign-hits-80-orgs-using.html)
- [How Threat Actors Abuse Remote Management Tools (Daisy-Chaining Rogue RMM Tools)](https://www.huntress.com/blog/daisy-chaining-rogue-rmm-tools)
- [AA25-163A: Ransomware Actors Exploit Unpatched SimpleHelp RMM to Compromise Utility Billing Software Provider](https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-163a)
- [AA23-025A: Protecting Against Malicious Use of Remote Monitoring and Management Software](https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-025a)
- [ConnectWise ScreenConnect Tops List of Abused RATs in 2025 Attacks](https://hackread.com/connectwise-screenconnect-tops-abused-rats-2025/)
- [Remote Access Software, Technique T1219 - Enterprise | MITRE ATT&CK](https://attack.mitre.org/techniques/T1219/)
- [Threat Actors Exploit LogMeIn Resolve, ScreenConnect in Phishing Campaigns](https://gbhackers.com/phishing-campaigns-3/)
- [Sordum - Hide From Uninstall List v1.1](https://www.sordum.org/downloads/?hide-from-uninstall-list=)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1820
