The Evolution of Remote Access Tool Abuse: From Single Payloads to Multi-Stage Campaigns
ID: e856216c-69eb-5e85-8f9e-1f1f319db32e
STIX ID: report--e856216c-69eb-5e85-8f9e-1f1f319db32e
Feed Name: Cofense Blog
Cofense Intelligence reports an increase in multi-stage campaigns where threat actors abuse legitimate remote access tools (ConnectWise, GoTo, Datto RMM, SimpleHelp, etc.) delivered via phishing to install initial RATs that contact C2 servers and retrieve secondary RATs and utilities for persistence; these chains enable initial access brokers to sell network access and complicate detection. The report includes multiple ATR-case examples, a noted upward trend in multi-stage RAT usage, and recommends layered defenses including employee phishing training, behavioral EDR, and whitelisting/curation of approved remote access tools.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
