External Remote Services

T1133

Technique.View on attack.mitre.org

About this technique

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.

Access to Valid Accounts to use the service is often a requirement, which could be obtained through credential pharming or by obtaining the credentials from users after compromising the enterprise network. Access to remote services may be used as a redundant or persistent access mechanism during an operation.

Access may also be gained through an exposed service that doesn’t require authentication. In containerized environments, this may include an exposed Docker API, Kubernetes API server, kubelet, or web application such as the Kubernetes dashboard.

Adversaries may also establish persistence on network by configuring a Tor hidden service on a compromised system. Adversaries may utilize the tool `ShadowLink` to facilitate the installation and configuration of the Tor hidden service. Tor hidden service is then accessible via the Tor network because `ShadowLink` sets up a .onion address on the compromised system. `ShadowLink` may be used to forward any inbound connections to RDP, allowing the adversaries to have remote access. Adversaries may get `ShadowLink` to persist on a system by masquerading it as an MS Defender application.

Detection rules56

Rules on DetectionCode tagged with T1133.

Sigma19

Splunk37

RuleTypeRiskData source
Cisco Network Interface ModificationsAnomalyNULLCisco IOS Logs
Confluence Unauthenticated Remote Code Execution CVE-2022-26134TTPNULLPalo Alto Network Threat
Detect attackers scanning for vulnerable JBoss serversTTPNULL
Detect Exchange Web ShellTTPNULLSysmon EventID 11
Exchange PowerShell Abuse via SSRFTTPNULL
Exploit Public Facing Application via Apache Commons TextAnomalyNULLNginx Access
Exploit Public-Facing Fortinet FortiNAC CVE-2022-39952TTPNULLPalo Alto Network Threat
F5 BIG-IP iControl REST Vulnerability CVE-2022-1388TTPNULLPalo Alto Network Threat
Fortinet Appliance Auth bypassTTPNULLPalo Alto Network Threat
Hunting for Log4ShellHuntingNULLNginx Access
Ivanti EPMM Remote Unauthenticated API Access CVE-2023-35078TTPNULLSuricata
Ivanti EPMM Remote Unauthenticated API Access CVE-2023-35082TTPNULLSuricata
Java Writing JSP FileTTPNULLSysmon for Linux EventID 1 AND Sysmon for Linux EventID 11
Linux Java Spawning ShellTTPNULLSysmon for Linux EventID 1
Living Off The Land DetectionCorrelationNULL

Groups28

Show 4 more

Software5

Campaigns10

Procedure examples43

Groups28

Used byProcedure example
GroupAkira

Akira uses compromised VPN accounts for initial access to victim networks.

GroupAPT-C-36

APT-C-36 has used VPNs in their operational infrastructure.

GroupAPT18

APT18 actors leverage legitimate credentials to log into external remote services.

GroupAPT28

APT28 has used Tor and a variety of commercial VPN services to route brute force authentication attempts.

GroupAPT29

APT29 has used compromised identities to access networks via VPNs and Citrix.

GroupAPT41

APT41 compromised an online billing/payment service using VPN access between a third-party service provider and the targeted payment service.

GroupChimera

Chimera has used legitimate credentials to login to an external VPN, Citrix, SSH, and other remote services.

GroupDragonfly

Dragonfly has used VPNs and Outlook Web Access (OWA) to maintain access to victim networks.

View all 28 groups examples

Software5

Used byProcedure example
MalwareDoki

Doki was executed through an open Docker daemon API port.

MalwareHildegard

Hildegard was executed through an unsecure kubelet that allowed anonymous access to the victim environment.

MalwareKinsing

Kinsing was executed in an Ubuntu container deployed via an open Docker daemon API.

MalwareLinux Rabbit

Linux Rabbit attempts to gain access to the server via SSH.

MalwareMafalda

Mafalda can establish an SSH connection from a compromised host to a server.

Campaigns10

Used byProcedure example
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team installed a modified Dropbear SSH client as the backdoor to target systems.

Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, threat actors leveraged the FortiGate VPN interface that was exposed to the internet to gain access to the victim environment.

CampaignArcaneDoor

ArcaneDoor used WebVPN sessions commonly associated with Clientless SSLVPN services to communicate to compromised devices.

CampaignC0027

During C0027, Scattered Spider used Citrix and VPNs to persist in compromised environments.

CampaignC0032

During the C0032 campaign, TEMP.Veles used VPN access to persist in the victim environment.

CampaignCostaRicto

During CostaRicto, the threat actors set up remote tunneling using an SSH tool to maintain access to a compromised environment.

CampaignNight Dragon

During Night Dragon, threat actors used compromised VPN accounts to gain access to victim systems.

CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors enabled WinRM over HTTP/HTTPS as a backup persistence mechanism using the following command: `cscript //nologo "C:\Windows\System32\winrm.vbs" set winrm/config/service@{EnableCompatibilityHttpsListener="true"}`.

View all 10 campaigns examples

References6

  1. MacOS VNC software for Remote Desktop Open source
    Apple Support. (n.d.). Set up a computer running VNC software for Remote Desktop. Retrieved August 18, 2021.
  2. Russian threat actors dig in, prepare to seize on war fatigue Open source
    Microsoft Threat Intelligence. (2023, December 7). Russian threat actors dig in, prepare to seize on war fatigue. Retrieved June 18, 2025.
  3. The BadPilot campaign Open source
    Microsoft Threat Intelligence. (2025, February 12). The BadPilot campaign: Seashell Blizzard subgroup conducts multiyear global access operation. Retrieved June 18, 2025.
  4. Trend Micro Exposed Docker Server Open source
    Remillano II, A., et al. (2020, June 20). XORDDoS, Kaiji Variants Target Exposed Docker Servers. Retrieved April 5, 2021.
  5. Unit 42 Hildegard Malware Open source
    Chen, J. et al. (2021, February 3). Hildegard: New TeamTNT Cryptojacking Malware Targeting Kubernetes. Retrieved April 5, 2021.
  6. Volexity Virtual Private Keylogging Open source
    Adair, S. (2015, October 7). Virtual Private Keylogging: Cisco Web VPNs Leveraged for Access and Persistence. Retrieved March 20, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.