Real-world descriptions of how a group, tool or campaign used a technique.
13 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1219 Remote Access Tools |
GroupBlackByte | BlackByte has used tools such as AnyDesk in victim environments. |
| T1219 Remote Access Tools |
GroupTeamTNT | TeamTNT has established tmate sessions for C2 communications. |
| T1219 Remote Access Tools |
GroupFIN7 | FIN7 has utilized the remote management tool Atera to download malware to a compromised system. |
| T1219 Remote Access Tools |
GroupSandworm Team | Sandworm Team has used remote administration tools or remote industrial control system client software for execution and to maliciously release electricity breakers. |
| T1219 Remote Access Tools |
GroupAkira | Akira uses legitimate utilities such as AnyDesk and PuTTy for maintaining remote access to victim environments. |
| T1219 Remote Access Tools |
GroupOilRig | OilRig has incorporated remote monitoring and management (RMM) tools into their operations including ngrok. |
| T1219 Remote Access Tools |
GroupCarbanak | Carbanak used legitimate programs such as AmmyyAdmin and Team Viewer for remote interactive C2 to target systems. |
| T1219 Remote Access Tools |
GroupDarkVishnya | DarkVishnya used DameWare Mini Remote Control for lateral movement. |
| T1219 Remote Access Tools |
GroupMedusa Group | Medusa Group has leveraged Remote Access Software for lateral movement and data exfiltration. Medusa Group has also been known to utilize Remote Access Software such as AnyDesk, Atera, ConnectWise, eHorus, N-Able, PDQ Deploy, PDQ Inventory, SimpleHelp and Splashtop. |
| T1219 Remote Access Tools |
GroupGOLD SOUTHFIELD | GOLD SOUTHFIELD has used the cloud-based remote management and monitoring tool "ConnectWise Control" to deploy REvil. |
| T1219 Remote Access Tools |
GroupINC Ransom | INC Ransom has used AnyDesk and PuTTY on compromised systems. |
| T1219 Remote Access Tools |
GroupCobalt Group | Cobalt Group used the Ammyy Admin tool as well as TeamViewer for remote access, including to preserve remote access if a Cobalt Strike module was lost. |
| T1219 Remote Access Tools |
GroupShinyHunters | ShinyHunters has used MeshCentral and ConnectWise to gain initial access, to run administrative command queries and to deploy the custom lateral movement and defacement script [victim_abbreviation]_fanout.sh. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.