Software Deployment Tools

T1072

Technique.View on attack.mitre.org

About this technique

Adversaries may gain access to and use centralized software suites installed within an enterprise to execute commands and move laterally through the network. Configuration management and software deployment applications may be used in an enterprise network or cloud environment for routine administration purposes. These systems may also be integrated into CI/CD pipelines. Examples of such solutions include: SCCM, HBSS, Altiris, AWS Systems Manager, Microsoft Intune, Azure Arc, and GCP Deployment Manager.

Access to network-wide or enterprise-wide endpoint management software may enable an adversary to achieve remote code execution on all connected systems. The access may be used to laterally move to other systems, gather information, or cause a specific effect, such as wiping the hard drives on all endpoints.

SaaS-based configuration management services may allow for broad Cloud Administration Command on cloud-hosted instances, as well as the execution of arbitrary commands on on-premises endpoints. For example, Microsoft Configuration Manager allows Global or Intune Administrators to run scripts as SYSTEM on on-premises devices joined to Entra ID. Such services may also utilize Web Protocols to communicate back to adversary owned infrastructure.

Network infrastructure devices may also have configuration management tools that can be similarly abused by adversaries.

The permissions required for this action vary by system configuration; local credentials may be sufficient with direct access to the third-party system, or specific domain credentials may be required. However, the system may require an administrative account to log in or to access specific functionality.

Detection rules9

Rules on DetectionCode tagged with T1072.

Sigma4

RuleLevelLog source
Restricted Software Access By SRPhighwindows / NULL
PDQ Deploy Remote Adminstartion Tool Executionmediumwindows / process_creation
PUA - Radmin Viewer Utility Executionmediumwindows / process_creation
Suspicious Csi.exe Usagemediumwindows / process_creation

Splunk5

RuleTypeRiskData source
Detection of tools built by NirSoftAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Microsoft Intune Device Health ScriptsHuntingNULLAzure Monitor Activity
Microsoft Intune DeviceManagementConfigurationPoliciesHuntingNULLAzure Monitor Activity
Microsoft Intune Manual Device ManagementHuntingNULLAzure Monitor Activity
Microsoft Intune Mobile AppsHuntingNULLAzure Monitor Activity

Groups8

Software1

Campaigns1

Procedure examples10

Groups8

Used byProcedure example
GroupAPT32

APT32 compromised McAfee ePO to move laterally by distributing malware as a software deployment task.

GroupMedusa Group

Medusa Group has utilized software deployment and management solutions to deploy their encryption payload to include BigFix and PDQ Deploy.

GroupMustang Panda

Mustang Panda has leveraged legitimate software tools such as AntiVirus Agents, Security Services, and App Development tools to execute scripts and to side-load dlls.

GroupSandworm Team

Sandworm Team has used the commercially available tool RemoteExec for agentless remote code execution.

GroupShinyHunters

ShinyHunters has abused software deployment tools for lateral movement.

GroupSilence

Silence has used RAdmin, a remote software tool used to remotely control workstations and ATMs.

GroupThreat Group-1314

Threat Group-1314 actors used a victim's endpoint management platform, Altiris, for lateral movement.

GroupVOID MANTICORE

VOID MANTICORE has leveraged legitimate built-in features of cloud-based management platforms to include mobile device management (MDM) and Remote Monitoring and Management (RMM) solutions. VOID MANTICORE has also initiated built-in remote wipe instructions using a privileged account within Microsoft Intune.

Software1

Used byProcedure example
MalwareWiper

It is believed that a patch management system for an anti-virus product commonly installed among targeted companies was used to distribute the Wiper malware.

Campaigns1

Used byProcedure example
CampaignC0018

During C0018, the threat actors used PDQ Deploy to move AvosLocker and tools across the network.

References3

  1. Fortinet Zero-Day and Custom Malware Used by Suspected Chinese Actor in Espionage Operation Open source
    ALEXANDER MARVI, BRAD SLAYBAUGH, DAN EBREO, TUFAIL AHMED, MUHAMMAD UMAIR, TINA JOHNSON. (2023, March 16). Fortinet Zero-Day and Custom Malware Used by Suspected Chinese Actor in Espionage Operation. Retrieved May 15, 2023.
  2. Mitiga Security Advisory: SSM Agent as Remote Access Trojan Open source
    Ariel Szarf, Or Aspir. (n.d.). Mitiga Security Advisory: Abusing the SSM Agent as a Remote Access Trojan. Retrieved January 31, 2024.
  3. SpecterOps Lateral Movement from Azure to On-Prem AD 2020 Open source
    Andy Robbins. (2020, August 17). Death from Above: Lateral Movement from Azure to On-Prem AD. Retrieved March 13, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.