By: Micah DeHarty, Intelligence Team
The Evolution of Remote Access Tool Abuse: From Single Payloads to Multi-Stage Campaigns
Cofense Intelligence has observed threat actors abusing legitimate remote access tools (RATs) using multiple attack stages to gain malicious access to victim machines, establish persistence in enterprise networks, and sell access to infected machines and networks. This type of attack has become increasingly common in early 2026. The attack chain for these multi-stage attacks typically starts with a phishing email containing an embedded link that leads to a malicious website. The malicious website then delivers the RAT onto the victim’s machine. When the RAT is installed, it reaches out to a command-and-control (C2) server. The C2 then provides another malicious URL used to download additional payloads if certain requirements are met. Threat actors are using these multi-stage attacks to ensure remote access is gained and to maintain persistence on the machine without the victim knowing. Threat actors who achieve persistence may then act as initial access brokers (IABs), monetizing their infection by selling access to infected computers and networks to one or more other threat actors. Attackers are using many different legitimate RATs for their attacks, such as ConnectWise RAT, N-Able RAT, SimpleHelp RAT, Datto RMM, and GoTo RAT. Each of these legitimate tools has unique capabilities such as enterprise familiarity, cloud hosted servers, command line execution, and low, and sometimes no, cost to use. Cofense Intelligence has seen each of these tools used in attacks with additional payloads leading to a different RAT than what was used in the initial download.
Key Points
- Threat actors are using legitimate RATs that download additional RATs as payloads.
- Abuse of RATs has shifted into more advanced attack chains.
- Attackers are abusing multiple different legitimate RATs to gain access to victim machines and persist in enterprise environments.
- Cofense Intelligence has seen an increase in attacks using multiple stages of RATs.
What Are Multi-Stage Remote Access Tools?
A remote access tool is typically a software application that allows a user, typically an administrator, to connect to and control a computer, server, or network from a different geographical location over the internet. These tools are typically used by technical support or remote workers for system administration or productivity. Threat actors abuse the capabilities of legitimate RATs to gain unwarranted access to victim machines. Using the remote access functionalities of these tools, threat actors are able to gain complete control of a target machine. Previously, threat actors would simply use one RAT to gain control of the target machine, but now they are utilizing more advanced, multi-stage techniques to gain access and maintain persistence. The initial infection typically stems from an embedded link in an email, but it can also come from an attached delivery mechanism, such as a document with an embedded link, or in more rare cases, an attached malicious script. The delivery mechanism will download the initial RAT and install it. Once installed, the initial RAT may automatically download a secondary RAT or retrieve one when instructed by a command-and-control (C2) server. After both stages are deployed, the threat actor gains control of the system and establishes persistence. In many cases, the second-stage payload is operated by a different threat actor, reflecting the division of roles commonly seen in IAB activity. Many times, the initial executable file is easy to find and uninstall because it is a legitimate tool used by IT staff. With multi-stage RATs, threat actors are able to download additional payloads and tools such as a tool from sordum[.]org that allows the threat actor to hide software from the Windows uninstall list. These additional payloads make it more difficult for security professionals to find and remove malicious software.
A Shift in Tactics
Multi-stage remote access trojans have been around for quite some time with malware families such as AsyncRAT, Remcos RAT, and XWorm RAT. While these malware families are still in use, in the past year the new trend in multi-stage RATs uses legitimate software such as GoTo RAT, ConnectWise RAT, and SimpleHelp RAT. In this context, the “T” in RAT can refer to either “Tool” or “Trojan,” depending on whether the software is legitimate or malicious. These legitimate tools have been abused by threat actors previously but had not been seen downloading additional RATs as often as they are now. Now attackers are delivering additional payloads after initial access is gained. These additional payloads include other legitimate RATs or other malicious tools used to supplement the original RAT. Cofense Intelligence has seen many variations and combinations of these legitimate tools being abused. Many times, threat actors use ConnectWise RAT as the second remote tool installed, but that is not the only second stage seen. This shift is a result of multiple factors but can largely be attributed to threat actors adapting to how their attacks are being monitored and prevented. As you can see in Figure 1 below, there is a steady upward trend of remote access attacks using multiple stages.

Figure 1: Line chart showing multi-stage RAT usage seen by Cofense Intelligence from January 2025 to March 2026.
One of the main reasons threat actors are using multi-stage RATs is to sell access to infected computers as an initial access broker, or IAB. IABs are threat actors who gain initial access to corporate networks, and then that access is sold to other threat actors. The initial infection is used solely for initial access to the target machine and is sold to another threat actor that provides the second or third stage of the infection.
Another reason threat actors are using multi-stage RATs is that each tool has different capabilities native to the tool. Some RATs, like ConnectWise RAT, have the ability to run PowerShell scripts internally in a way that reduces PowerShell execution logs. Other RATs only allow for the bare minimum in access, so it is necessary for threat actors to use an additional payload to gain full access to the victim’s machine. The delivery of multiple RATs allows threat actors to maintain multiple C2s. C2s allow the threat actor to both exfiltrate data and load additional malware onto the machine. With multiple C2s, it is harder for security teams to find all of the network artifacts and block them as well as providing threat actors with redundancy if one of the C2s is blocked. While it may be less covert to have multiple RATs and multiple C2s, it gives threat actors more opportunity to have a successful attack and maintain persistence.
Real-Life Examples
Cofense Intelligence has seen many different examples of multi-stage RAT campaigns. There are many combinations of tools being used and different methods of infection. Cofense Intelligence maintains a database of Active Threat Reports (ATR) within the ThreatHQ platform. These ATRs detail different threats seen by our Intelligence team, such as credential phishing and different types of malware delivered via email, as well as the context of the campaign detailed in the ATR. In ATR 409595, a threat actor uses an Adobe-spoofing email to deliver GoTo RAT. In the email, the threat actor states that the recipient needs to access a file using Adobe Cloud. The email in Figure 2 contains a link to a fake Adobe Cloud page that states the user’s Adobe PDF viewer is out of date. The link to update the software then initiates the download of the GoTo RAT executable file. After the executable is downloaded and installed, the GoTo RAT reaches out to a C2 server and is directed to download ConnectWise RAT. ConnectWise RAT is then installed without the victim knowing.
Figure 2: Phishing email from ATR 409595 spoofing Adobe Cloud delivering a multi-stage remote access attack.
Figure 3: Attack chain diagram for ATR 409595.
In ATR 409165 shown in Figure 4 below, Cofense Intelligence observed a threat actor delivering Datto RMM with an additional download of ConnectWise RAT delivered by the Datto RMM. The attacker is using trust or familiarity to get the recipient to click an embedded link. This attack follows a similar attack chain to the one seen in ATR 409595 but with the use of Datto RMM instead of GoTo RAT. There are not many differences that would lead to the use of one first-stage RAT over another. In comparison, both the Datto RMM from ATR 409165 and the GoTo RAT from ATR 409595 are used in the same manner. The initial RAT is used to gain a foothold on the system and is directed to download additional payloads by a C2 server. In both cases, ConnectWise was the second-stage RAT downloaded, but that is not always the case.
Figure 4: Title company-spoofing email from ATR 409165 used to deliver multi-stage remote access attack.
Figure 5: Attack chain diagram for ATR 409165.
In another attack seen in Figure 6, ATR 408664, a threat actor uses an invitation-themed email to deliver SimpleHelp RAT. When the user clicks on the link to accept the fake invitation, they are directed to a website that impersonates the invitation website. This spoofed website then tells the user to click another link to download their personalized invitation. This link instead downloads a malicious SimpleHelp RAT executable. Once downloaded and installed, the SimpleHelp RAT reaches out to a preconfigured C2 server. That C2 server then directs SimpleHelp RAT to download ConnectWise RAT.
Figure 6: Invitation-themed email from ATR 408664 used to deliver multi-stage remote access attack.
Figure 7: Attack chain diagram for ATR 408664.
As seen in all three of the above samples, attackers are using what could previously be considered simple RATs and turning them into advanced, multi-staged attacks. Each attack involved a legitimate RAT that reached out to a C2 server which then directed it to download another legitimate RAT.
Figure 8: Document-themed email from ATR 410324 delivered ConnectWise RAT and Heartbeat RM.
Figure 9: Attack chain diagram for ATR 410324.
In this final example from ATR 410324, a threat actor uses ConnectWise RAT as the first stage of their remote access attack. As seen in Figure 8, the email roughly imitates an email to notify the user that their signed documents are ready to view. When the user clicks the button to view their documents, an embedded link directs them to a page that downloads ConnectWise RAT. Once this ConnectWise RAT executable is run and installed, the C2 server directs the RAT to additional payload URLs that download Heartbeat RM and an additional ConnectWise RAT. This attack also downloads the “hide from uninstall list” utility from sordum[.]org. This multi-stage attack not only contains multiple legitimate RATs but also abuses technically legitimate utilities to hide the attack from defenders.
Conclusion
Threat actors continue to evolve their tactics using legitimate RATs. One evolution seen recently by Cofense Intelligence is the abuse of multi-stage RATs. Attackers are using legitimate tools such as ConnectWise RAT, GoTo RAT, Datto RMM, and others to deliver second stages that use different RATs. With a more advanced attack chain, defenders must also advance defense tactics. Multi-stage, modular attacks require advanced behavioral alerting and prevention tools. Context is especially valuable when analyzing and preventing these attacks, because the legitimacy of an individual tool, process, or network connection may only become suspicious when viewed as part of the broader infection chain, delivery method, and follow-on activity.
Remediation
Because these attacks have multiple stages and are modular, defense requires a layered approach.
- Employee training can stop attacks before they start. Training employees to recognize these phishing attempts is a vital first step. The attacks detailed in the examples above bypassed email security technologies and were reported by trained employees using the Cofense report phishing button.
- Implementing proper security tools such as behavioral-based Endpoint Detection and Response (EDR) can help detect malicious activity instead of just alerting on static file signatures.
- Maintain and curate a list of approved remote access tools. Having a designated list of approved legitimate tools makes it clear when deployment of non-approved tools, whether maliciously intended or not, is a violation of security policy. This makes it easy to determine if a technically legitimate tool should be removed from a system.