Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1021.002 SMB/Windows Admin Shares |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used SMB for lateral movement. |
| T1021.002 SMB/Windows Admin Shares |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used administrative accounts to connect over SMB to targeted users. |
| T1021.002 SMB/Windows Admin Shares |
CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 leveraged SMB to transfer files and move laterally. |
| T1021.002 SMB/Windows Admin Shares |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team utilized `net use` to connect to network shares. |
| T1021.002 SMB/Windows Admin Shares |
CampaignOperation Wocao | During Operation Wocao, threat actors used Impacket's smbexec.py as well as accessing the C$ and IPC$ shares to move laterally. |
| T1021.002 SMB/Windows Admin Shares |
CampaignLeviathan Australian Intrusions | Leviathan used remote shares to move laterally through victim networks during Leviathan Australian Intrusions. |
| T1021.002 SMB/Windows Admin Shares |
GroupBlackByte | BlackByte used SMB file shares to distribute payloads throughout victim networks, including BlackByte ransomware variants during wormable operations. |
| T1021.002 SMB/Windows Admin Shares |
GroupAPT3 | APT3 will copy files over to Windows Admin Shares (like ADMIN$) as part of lateral movement. |
| T1021.002 SMB/Windows Admin Shares |
GroupAPT41 | APT41 has transferred implant files using Windows Admin Shares and the Server Message Block (SMB) protocol, then executes files through Windows Management Instrumentation (WMI). |
| T1021.002 SMB/Windows Admin Shares |
GroupAPT32 | APT32 used Net to use Windows' hidden network shares to copy their tools to remote machines for execution. |
| T1021.002 SMB/Windows Admin Shares |
GroupStorm-1811 | Storm-1811 has attempted to move laterally in victim environments via SMB using Impacket. |
| T1021.002 SMB/Windows Admin Shares |
GroupSandworm Team | Sandworm Team has copied payloads to the `ADMIN$` share of remote systems and run |
| T1021.002 SMB/Windows Admin Shares |
GroupAPT39 | APT39 has used SMB for lateral movement. |
| T1021.002 SMB/Windows Admin Shares |
GroupMoses Staff | Moses Staff has used batch scripts that can enable SMB on a compromised host. |
| T1021.002 SMB/Windows Admin Shares |
GroupOrangeworm | Orangeworm has copied its backdoor across open network shares, including ADMIN$, C$WINDOWS, D$WINDOWS, and E$WINDOWS. |
| T1021.002 SMB/Windows Admin Shares |
GroupAquatic Panda | Aquatic Panda used remote shares to enable lateral movement in victim environments. |
| T1021.002 SMB/Windows Admin Shares |
GroupKe3chang | Ke3chang actors have been known to copy files to the network shares of other computers to move laterally. |
| T1021.002 SMB/Windows Admin Shares |
GroupBlue Mockingbird | Blue Mockingbird has used Windows Explorer to manually copy malicious files to remote hosts over SMB. |
| T1021.002 SMB/Windows Admin Shares |
GroupTurla | Turla used |
| T1021.002 SMB/Windows Admin Shares |
GroupCinnamon Tempest | Cinnamon Tempest has used SMBexec for lateral movement. |
| T1021.002 SMB/Windows Admin Shares |
GroupChimera | Chimera has used Windows admin shares to move laterally. |
| T1021.002 SMB/Windows Admin Shares |
GroupMirrorFace | MirrorFace has used SMB to copy malware between systems in compromised environments. |
| T1021.002 SMB/Windows Admin Shares |
GroupDeep Panda | Deep Panda uses net.exe to connect to network shares using |
| T1021.002 SMB/Windows Admin Shares |
GroupToddyCat | ToddyCat has used locally mounted network shares for lateral movement through targated environments. |
| T1021.002 SMB/Windows Admin Shares |
GroupAPT28 | APT28 has mapped network drives using Net and administrator credentials. |
| T1021.002 SMB/Windows Admin Shares |
GroupFox Kitten | Fox Kitten has used valid accounts to access SMB shares. |
| T1021.002 SMB/Windows Admin Shares |
GroupLazarus Group | Lazarus Group malware SierraAlfa accesses the |
| T1021.002 SMB/Windows Admin Shares |
GroupThreat Group-1314 | Threat Group-1314 actors mapped network drives using |
| T1021.002 SMB/Windows Admin Shares |
GroupWizard Spider | Wizard Spider has used SMB to drop Cobalt Strike Beacon on a domain controller for lateral movement. |
| T1021.002 SMB/Windows Admin Shares |
GroupVelvet Ant | Velvet Ant has transferred tools within victim environments using SMB. |
| T1021.002 SMB/Windows Admin Shares |
GroupPlay | Play has used Cobalt Strike to move laterally via SMB. |
| T1021.002 SMB/Windows Admin Shares |
GroupFIN8 | FIN8 has attempted to map to C$ on enumerated hosts to test the scope of their current credentials/context. FIN8 has also used smbexec from the Impacket suite for lateral movement. |
| T1021.002 SMB/Windows Admin Shares |
GroupFIN13 | FIN13 has leveraged SMB to move laterally within a compromised network via application servers and SQL servers. |
| T1021.002 SMB/Windows Admin Shares |
MalwareStuxnet | Stuxnet propagates to available network shares. |
| T1021.002 SMB/Windows Admin Shares |
MalwarereGeorg | reGeorg has the ability to tunnel SMB sessions. |
| T1021.002 SMB/Windows Admin Shares |
MalwareRansomHub | RansomHub can use credentials provided in its configuration to move laterally from the infected machine over SMBv2. |
| T1021.002 SMB/Windows Admin Shares |
MalwareEmotet | Emotet has leveraged the Admin$, C$, and IPC$ shares for lateral movement. |
| T1021.002 SMB/Windows Admin Shares |
MalwareOlympic Destroyer | Olympic Destroyer uses PsExec to interact with the |
| T1021.002 SMB/Windows Admin Shares |
MalwareRegin | The Regin malware platform can use Windows admin shares to move laterally. |
| T1021.002 SMB/Windows Admin Shares |
MalwareConti | Conti can spread via SMB and encrypts files on different hosts, potentially compromising an entire network. |
| T1021.002 SMB/Windows Admin Shares |
MalwareDiavol | Diavol can spread throughout a network via SMB prior to encryption. |
| T1021.002 SMB/Windows Admin Shares |
MalwareLucifer | Lucifer can infect victims by brute forcing SMB. |
| T1021.002 SMB/Windows Admin Shares |
MalwareBlackEnergy | BlackEnergy has run a plug-in on a victim to spread through the local network by using PsExec and accessing admin shares. |
| T1021.002 SMB/Windows Admin Shares |
MalwarezwShell | zwShell has been copied over network shares to move laterally. |
| T1021.002 SMB/Windows Admin Shares |
MalwareNotPetya | NotPetya can use PsExec, which interacts with the |
| T1021.002 SMB/Windows Admin Shares |
MalwareConficker | Conficker variants spread through NetBIOS share propagation. |
| T1021.002 SMB/Windows Admin Shares |
MalwareAnchor | Anchor can support windows execution via SMB shares. |
| T1021.002 SMB/Windows Admin Shares |
MalwareLockBit 3.0 | LockBit 3.0 can use SMB for lateral movement. |
| T1021.002 SMB/Windows Admin Shares |
MalwareRoyal | Royal can use SMB to connect to move laterally. |
| T1021.002 SMB/Windows Admin Shares |
MalwareShamoon | Shamoon accesses network share(s), enables share access to the target device, copies an executable payload to the target system, and uses a Scheduled Task/Job to execute the malware. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.