ATT&CKSoftwareConnectWise

ConnectWise

S0591

Tool.View on attack.mitre.org

About this tool

ConnectWise is a legitimate remote administration tool that has been used since at least 2016 by threat actors including MuddyWater and GOLD SOUTHFIELD to connect to and conduct lateral movement in target environments.

Techniques used3

Procedure examples3

TechniqueProcedure example
T1059.001
PowerShell

ConnectWise can be used to execute PowerShell commands on target machines.

T1113
Screen Capture

ConnectWise can take screenshots on remote hosts.

T1125
Video Capture

ConnectWise can record video on remote hosts.

Groups that use it3

Campaigns0

None recorded.

References2

  1. Anomali Static Kitten February 2021 Open source
    Mele, G. et al. (2021, February 10). Probable Iranian Cyber Actors, Static Kitten, Conducting Cyberespionage Campaign Targeting UAE and Kuwait Government Agencies. Retrieved March 17, 2021.
  2. Trend Micro Muddy Water March 2021 Open source
    Peretz, A. and Theck, E. (2021, March 5). Earth Vetala – MuddyWater Continues to Target Organizations in the Middle East. Retrieved March 18, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.