VNC

T1021.005

Sub-technique of T1021 Remote Services.View on attack.mitre.org

About this technique

Adversaries may use Valid Accounts to remotely control machines using Virtual Network Computing (VNC). VNC is a platform-independent desktop sharing system that uses the RFB (“remote framebuffer”) protocol to enable users to remotely control another computer’s display by relaying the screen, mouse, and keyboard inputs over the network.

VNC differs from Remote Desktop Protocol as VNC is screen-sharing software rather than resource-sharing software. By default, VNC uses the system's authentication, but it can be configured to use credentials specific to VNC.

Adversaries may abuse VNC to perform malicious actions as the logged-on user such as opening documents, downloading files, and running arbitrary commands. An adversary could use VNC to remotely control and monitor a system to collect data and information to pivot to other systems within the network. Specific VNC libraries/implementations have also been susceptible to brute force attacks and memory usage exploitation.

Detection rules1

Rules on DetectionCode tagged with T1021.005.

Sigma1

RuleLevelLog source
Suspicious UltraVNC Executionhighwindows / process_creation

Splunk0

No Splunk rules are mapped to this technique yet.

Groups4

Software7

Campaigns0

None recorded.

Procedure examples11

Groups4

Used byProcedure example
GroupFIN7

FIN7 has used TightVNC to control compromised hosts.

GroupFox Kitten

Fox Kitten has installed TightVNC server and client on compromised servers and endpoints for lateral movement.

GroupGamaredon Group

Gamaredon Group has used VNC tools, including UltraVNC, to remotely interact with compromised hosts.

GroupGCMAN

GCMAN uses VNC for lateral movement.

Software7

Used byProcedure example
MalwareCarberp

Carberp can start a remote VNC session by downloading a new plugin.

MalwareDanBot

DanBot can use VNC for remote access to targeted systems.

MalwareLatrodectus

Latrodectus has routed C2 traffic using Keyhole VNC.

MalwareProton

Proton uses VNC to connect into systems.

MalwareTrickBot

TrickBot has used a VNC module to monitor the victim and collect information to pivot to valuable systems on the network

MalwareWarzoneRAT

WarzoneRAT has the ability of performing remote desktop access via a VNC console.

MalwareZxShell

ZxShell supports functionality for VNC sessions.

References9

  1. Attacking VNC Servers PentestLab Open source
    Administrator, Penetration Testing Lab. (2012, October 30). Attacking VNC Servers. Retrieved October 6, 2021.
  2. Havana authentication bug Open source
    Jay Pipes. (2013, December 23). Security Breach! Tenant A is seeing the VNC Consoles of Tenant B!. Retrieved September 12, 2024.
  3. Hijacking VNC Open source
    Z3RO. (2019, March 10). Day 70: Hijacking VNC (Enum, Brute, Access and Crack). Retrieved September 20, 2021.
  4. MacOS VNC software for Remote Desktop Open source
    Apple Support. (n.d.). Set up a computer running VNC software for Remote Desktop. Retrieved August 18, 2021.
  5. Offensive Security VNC Authentication Check Open source
    Offensive Security. (n.d.). VNC Authentication. Retrieved October 6, 2021.
  6. The Remote Framebuffer Protocol Open source
    T. Richardson, J. Levine, RealVNC Ltd.. (2011, March). The Remote Framebuffer Protocol. Retrieved September 20, 2021.
  7. VNC Authentication Open source
    Tegan. (2019, August 15). Setting up System Authentication. Retrieved September 20, 2021.
  8. VNC Vulnerabilities Open source
    Sergiu Gatlan. (2019, November 22). Dozens of VNC Vulnerabilities Found in Linux, Windows Solutions. Retrieved September 20, 2021.
  9. macOS root VNC login without authentication Open source
    Nick Miles. (2017, November 30). Detecting macOS High Sierra root account without authentication. Retrieved September 20, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.