T1219Remote Access Tools
T1219 — Remote Access Tools is a MITRE ATT&CK technique in the Command and Control tactic. Clankerusecase tracks 29 detection use cases covering it and 78 threat-intel articles citing it.
Command and Control
29Use cases
78Articles
3Sub-techniques
1Tactic
Sub-techniques (3)
Use cases covering this technique (29)
RMM tool installed by non-IT user — remote-access utility for hands-on-keyboard Detect Remote Access Software Usage File Detect Remote Access Software Usage FileInfo Detect Remote Access Software Usage Process Detect Remote Access Software Usage Registry Windows Level RMM PowerShell Script Installer Windows Level RMM Watchdog Task Created Windows Remote Access Software BRC4 Loaded Dll Windows Remote Access Software RMS Registry Windows RMM Tool Execution Cisco Secure Firewall - Communication Over Suspicious Ports Cisco Secure Firewall - Remote Access Software Usage Traffic Detect Remote Access Software Usage DNS Detect Remote Access Software Usage Traffic HTTP RMM User Agent Detect Remote Access Software Usage URL Windows Remote Access Software Hunt [LLM] esxi.sh downloader deploys architecture-specific reverse_ssh from 185.144.28.120 [LLM] Managed endpoint network egress to DPRK IT-worker VPS / AstrillVPN IPs [LLM] Reverse-shell egress from Flowise node process tree (nc/shell child dialing out) [LLM] AnyDesk silent/unattended install used for DragonForce access [LLM] Trojanized MeshAgent running outside its install path (Sinobi ransomware C2) [LLM] Zoho Assist Unattended Agent deployment (Warlock / Storm-2603 ransomware) [LLM] Trojanized MeshAgent installed as SYSTEM auto-start service (Sinobi covert C2) [LLM] Zoho Assist Unattended Agent deployment for headless remote access (Warlock / Storm-2603) [LLM] Outbound C2 to PlugX/ShadowPad/Cobalt Strike/Remcos infrastructure targeting Pakistani law enforcement [LLM] OpenClaw Gateway WebSocket listener / loopback connection on TCP 18789 [LLM] MuddyWater SimpleHelp RMM client spawning shell or recon LOLBin [LLM] ScreenConnect MSI sideload from lmfao.su (Solidity Language post-exploit RAT install)Articles citing this technique (78)
crit Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware art-28
high DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt art-82
crit Begun, the Patch Wars have art-253
crit CISA KEV: CVE-2025-3935 — ConnectWise ScreenConnect Improper Authentication Vulnerability art-968
crit CISA KEV: CVE-2024-1709 — ConnectWise ScreenConnect Authentication Bypass Vulnerability art-1419
high SREs bring ORDER(R) to CHAOS art-1988
med How Onna Technologies uses Snyk & Sysdig to secure the SDLC while saving time and money art-2039
high Securing PHP containers art-2105
med Cloud security challenges art-2270