FORENSIA

ATT&CK · T1219

Remote Access Tools

Tactics: command-and-control

About

An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools create a session between two trusted hosts through a graphical interface, a command line interaction, a protocol tunnel via development or management software, or hardware-level access such as KVM (Keyboard, Video, Mouse) over IP solutions. Desktop support software (usually graphical interface) and remote management software (typically command line interface) allow a user to control a computer remotely as if they are a local user inheriting the user or software permissions. This software is commonly used for troubleshooting, software installation, and system management. Adversaries may similarly abuse response features included in EDR and other defensive tools that enable remote access. Remote access tools may be installed and used post-compromise as an alternate communications channel for redundant access or to establish an interactive remote desktop session with the target system. It may also be used as a malware component to establish a reverse connection or back-connect to a service or adversary-controlled system. Installation of many remote access tools may also include persistence (e.g., the software's installation routine creates a Windows Service). Remote access modules/features may also exist as part of otherwise existing software (e.g., Google Chrome’s Remote Desktop).

Platforms: Linux, macOS, WindowsMITRE ATT&CK ↗

Used by actors

12 known groups

Software

7 malware/tools implement this

CarbanakRTMTrickBotDridexEgregorHildegardInvisibleFerret

Corpus indicators tagged with this technique

1,048 indicators in the corpus carry T1219.

IndicatorTypeFamilySevSrc
cve-2026-4368cveransomware851
6c39900d77dcba158e1d27c7619cb06dhash801
16bad42a397db2e075e09b5b9dd53aaa67b495a4hashransomware801
dc9938f51150d13a69fc25f3f19052eacb1bf0a086fd5cf39762501fb3ddd7dahashransomware801
0ba93109757776a44de9d8c88baa4963hash801
66442f2457eca8f47385b1fb2c6fcab8hash801
6bf155b269d452f3c3b62832b27bbebe4da436e228dbf521155b1d5989e3743fhashransomware801
5cc212f84d2bf3fbab165aaf09b16e00fcf2f1ccd880d24b14404c53dcdbf241hashransomware801
8d1a22c430252f29611766b8e4a82af0fba60d609246463466b384d6d4793df4hashransomware801
bf8c45e5aa9551a17eefbd1d179422c32b4309c47ee9a3f315bb80ed6d4f7efchashransomware801
887ec87e4a19759cad25d4bc0956d2b965d3041dhash801
31037a42ca048e06e69a78f55bc2eff5hash801
47854deb456cb08c651b7f9ae2f9d87c72d0719de6af233340632efb3c1980f4sha256phishing801
63ac85195b73753333316a889cf5880fhash801
f6a01d0246ce31faf6938ea488086d4358505405a4ef5c5faa482e79e92cb347hashransomware801
6cd349eda0fa6c8b274a0920852c68f8b727afea1fdbc69ad183cef05d9cf141hashransomware801
31800380c359143ae82c4f9011eee653dd22443d03d6a499148203bbfc275502hashransomware801
24f6c0ca39b2a5593086ff56d818ddfbde121f8e44d54faa762e510397dc9db7hashransomware801
686213cc11d36af764de824801bced9366dfca3823fe0d51b752f74149bcf1f4sha256ransomware801
7f37351979c249417cb180b4ede0ed17e5fe2a1f08add4d72606b589f8fdb245hashransomware801
90e46e89fec2108a1cb4850bb33e3563e92a14d04e1e613ac8c9311f152d294chashransomware801
97aebda5482899fef84a24e456bff055acaa47e5ab4029f768d9e0c62a660ce2hashransomware801
9e5b1e10ad6904d3f5b48d38470cd57263974640a27d13cf793ef026d3d6b886hash802
fab69acd743f4111b749e3268690825c38822e62hash802
44f6101dd8171133f53317bfd752300ehash802
f57e010541fb4ccbf23aefc4a827f753a6ff3f8792d9c04c3eea83f6963c6baesha256phishing801
91e523a46f3bb860ac2e5800b7e1ec89d75a2408410b9cd25eebc17c8d7a92bchash802
99813f3d0625e880158c68039c0e2fbf488db0be3db77cd1ce6d382644193f0ehash802
2c6f05f1f309d89b2236e6c8b59c88f9hash801
02bb20455cc592a69c080abac770ce90hash801

Showing the top 30 by severity of 1,048.