T1219Remote Access Tools
T1219 — Remote Access Tools is a MITRE ATT&CK technique in the Command and Control tactic. Clankerusecase tracks 30 detection use cases covering it and 70 threat-intel articles citing it.
Command and Control
30Use cases
70Articles
3Sub-techniques
1Tactic
Sub-techniques (3)
Use cases covering this technique (30)
RMM tool installed by non-IT user — remote-access utility for hands-on-keyboard Detect Remote Access Software Usage File Detect Remote Access Software Usage FileInfo Detect Remote Access Software Usage Process Detect Remote Access Software Usage Registry Windows Level RMM PowerShell Script Installer Windows Level RMM Watchdog Task Created Windows Remote Access Software BRC4 Loaded Dll Windows Remote Access Software RMS Registry Windows RMM Tool Execution Cisco Secure Firewall - Communication Over Suspicious Ports Cisco Secure Firewall - Remote Access Software Usage Traffic Detect Remote Access Software Usage DNS Detect Remote Access Software Usage Traffic HTTP RMM User Agent Detect Remote Access Software Usage URL Windows Remote Access Software Hunt [LLM] GS-Netcat Relay C2 (gs.thc.org) + systemd Persistence Service [LLM] MeshCentral agent disguised as Microsoft Azure binary calling azurenetfiles.net [LLM] AGENTPSD-style Python reverse shell spawned by sshd on Linux / NAS [LLM] Quick Assist launched followed by remote interactive session (UNC3753 vishing pretext) [LLM] AnyDesk, Bomgar, SuperOps or Zoho Assist installer execution (UNC3753 RMM foothold) [LLM] Reverse-shell /dev/tcp file descriptor from Yamcs java process tree [LLM] OpenSSH reverse port-forward (-R) launched on a workstation - Cloud Atlas backup C2 [LLM] OpenClaw Gateway WebSocket listener / loopback connection on TCP 18789 [LLM] MuddyWater SimpleHelp RMM client spawning shell or recon LOLBin [LLM] PromptSpy VNC C2 egress to 54.67.2.84 [LLM] ScreenConnect client beaconing to ClawdBot attacker relay (meeting.bulletmailer.net:8041) [LLM] Weaponised ScreenConnect install path with attacker instance GUID 083e4d30c7ea44f7 [LLM] ScreenConnect MSI sideload from lmfao.su (Solidity Language post-exploit RAT install)Articles citing this technique (70)
crit ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities art-37
high A tale of two eras art-40
crit Researchers Build Self-Replicating AI Worm That Operates Entirely on Local, Open-Weight Models art-87
crit Microsoft is named a Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection art-178
crit Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload art-219