ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1021.001×

17 examples

TechniqueUsed byProcedure example
T1021.001
Remote Desktop Protocol
MalwarereGeorg

reGeorg can be used to tunnel RDP connections.

T1021.001
Remote Desktop Protocol
MalwareDarkComet

DarkComet can open an active screen of the victim’s machine and take control of the mouse and keyboard.

T1021.001
Remote Desktop Protocol
MalwarezwShell

zwShell has used RDP for lateral movement.

T1021.001
Remote Desktop Protocol
MalwareCarbanak

Carbanak enables concurrent Remote Desktop Protocol (RDP) sessions.

T1021.001
Remote Desktop Protocol
MalwareSDBbot

SDBbot has the ability to use RDP to connect to victim's machines.

T1021.001
Remote Desktop Protocol
MalwarePysa

Pysa has laterally moved using RDP connections.

T1021.001
Remote Desktop Protocol
MalwareCobalt Strike

Cobalt Strike can start a VNC-based remote desktop server and tunnel the connection through the already established C2 channel.

T1021.001
Remote Desktop Protocol
MalwareServHelper

ServHelper has commands for adding a remote desktop user and sending RDP traffic to the attacker through a reverse SSH tunnel.

T1021.001
Remote Desktop Protocol
MalwareRevenge RAT

Revenge RAT has a plugin to perform RDP access.

T1021.001
Remote Desktop Protocol
MalwareZxShell

ZxShell has remote desktop functionality.

T1021.001
Remote Desktop Protocol
MalwarenjRAT

njRAT has a module for performing remote desktop access.

T1021.001
Remote Desktop Protocol
MalwarejRAT

jRAT can support RDP control.

T1021.001
Remote Desktop Protocol
MalwareWarzoneRAT

WarzoneRAT has the ability to control an infected PC using RDP.

T1021.001
Remote Desktop Protocol
ToolImminent Monitor

Imminent Monitor has a module for performing remote desktop access.

T1021.001
Remote Desktop Protocol
ToolKoadic

Koadic can enable remote desktop on the victim's machine.

T1021.001
Remote Desktop Protocol
ToolPupy

Pupy can enable/disable RDP connection and can start a remote desktop session using a browser web socket client.

T1021.001
Remote Desktop Protocol
ToolQuasarRAT

QuasarRAT has a module for performing remote desktop access.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.