ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1219.002×

11 examples

TechniqueUsed byProcedure example
T1219.002
Remote Desktop Software
GroupKimsuky

Kimsuky has used a modified TeamViewer client as a command and control channel.

T1219.002
Remote Desktop Software
GroupEvilnum

EVILNUM has used the malware variant, TerraTV, to run a legitimate TeamViewer application to connect to compromised machines.

T1219.002
Remote Desktop Software
GroupMuddyWater

MuddyWater has leveraged RMM solutions including ScreenConnect, AteraAgent, SimpleHelp, Action1, Level, and PDQ to facilitate follow-on actions within compromised hosts to include data exfiltration.

T1219.002
Remote Desktop Software
GroupStorm-1811

Storm-1811 has abused multiple types of legitimate remote access software and tools, such as ScreenConnect, NetSupport Manager, and AnyDesk.

T1219.002
Remote Desktop Software
GroupMustang Panda

Mustang Panda has installed TeamViewer on targeted systems.

T1219.002
Remote Desktop Software
GroupScattered Spider

In addition to directing victims to run remote software, Scattered Spider members themselves also deploy RMM software including TeamViewer, AnyDesk, LogMeIn, ngrok, and ConnectWise to establish persistence on the compromised network.

T1219.002
Remote Desktop Software
GroupContagious Interview

Contagious Interview has downloaded remote management and monitoring software such as “AnyDesk” for post compromise activities.

T1219.002
Remote Desktop Software
GroupStorm-0501

Storm-0501 has used legitimate remote monitoring and management (RMM) tools including AnyDesk, NinjaOne, and Level.io.

T1219.002
Remote Desktop Software
GroupRTM

RTM has used a modified version of TeamViewer and Remote Utilities for remote access.

T1219.002
Remote Desktop Software
GroupThrip

Thrip used a cloud-based remote access software called LogMeIn for their attacks.

T1219.002
Remote Desktop Software
GroupVOID MANTICORE

VOID MANTICORE has installed NetBird on victim devices to create a mesh network that facilitated control of several victim devices at once.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.