T1219 - Remote Access Tools - MITRE ATT&CK

Threat entity extracted from intelligence sources

Frequency
6
occurrences
First Seen
March 20, 2026
Last Seen
July 9, 2026

T1219 - Remote Access Tools is a mitre_attack tracked across 6 threat clusters and 6 intelligence report mentions on ThreatCluster. First observed March 20, 2026; most recent activity July 9, 2026.

Related Threat Clusters

  • Ransomware Toolkit Exposed: TheGentlemen Affiliate's Operations Uncovered

    Researchers found an exposed server on a Russian bulletproof hosting provider containing a complete ransomware toolkit linked to TheGentlemen affiliate. The toolkit includes various utilities for credential dumping,…

    3 articles · Updated March 30, 2026
  • New Remcos RAT Campaign Exploits CVE-2017-11882 via Phishing

    A new phishing campaign distributing a variant of the Remcos RAT has been identified, targeting Microsoft Windows users. The attack utilizes a fake shipping document to deliver a malicious Word file that exploits…

    2 articles · Updated May 29, 2026
  • Scattered Spider Reclassified as Decentralized Cybercrime Collective

    Scattered Spider, a cybercrime entity linked to various high-profile attacks since 2022, has been reclassified as a decentralized collective rather than a unified group. Group-IB's analysis indicates that it consists of…

    2 articles · Updated July 7, 2026
  • Phishing Campaigns Evolve to Target Specific Devices and Operating Systems

    Recent research indicates a significant evolution in phishing tactics, with threat actors moving from generic attacks to sophisticated, platform-aware campaigns. These modern phishing operations utilize user-agent data…

    2 articles · Updated July 1, 2026
  • Ransomware Fuels Surge in Global Cyberattacks

    As of February 12, 2026, organizations worldwide are experiencing an average of 2,090 cyber-attacks per week, largely driven by ransomware incidents. This increase highlights the ongoing challenges faced by businesses…

    1554 articles · Updated February 12, 2026
  • Beast Ransomware Toolkit Exposed in Open Directory Incident

    An open server linked to the Beast ransomware group was discovered, revealing their extensive toolkit and attack methods. This ransomware-as-a-service (RaaS) group, active since June 2024, is believed to be a successor…

    2 articles · Updated March 20, 2026

Recent Intelligence Reports

  • GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses — Security · July 9, 2026
  • Scattered Spider’s Structure More Like a Cybercrime Collective Than a Unified Gang — Infosecurity-Magazine · July 7, 2026
  • Crafty Phishing Campaigns Auto-Adapt to Victim's Device, OS — Darkreading · July 1, 2026
  • Deceptively Sweet: DonutLoader Reloaded in a modern Remcos RAT Infection — Feeds.Feedburner · May 29, 2026
  • Exposed Ransomware Toolkit Tied to TheGentlemen Affiliate — Socprime · March 30, 2026
  • Cyber OpSec Fail: Beast Gang Exposes Ransomware Server — Darkreading · March 20, 2026

CVSS v3.1 Breakdown