Lateral Tool Transfer

T1570

Technique.View on attack.mitre.org

About this technique

Adversaries may transfer tools or other files between systems in a compromised environment. Once brought into the victim environment (i.e., Ingress Tool Transfer) files may then be copied from one system to another to stage adversary tools or other files over the course of an operation.

Adversaries may copy files between internal victim systems to support lateral movement using inherent file sharing protocols such as file sharing over SMB/Windows Admin Shares to connected network shares or with authenticated connections via Remote Desktop Protocol.

Files can also be transferred using native or otherwise present tools on the victim system, such as scp, rsync, curl, sftp, and ftp. In some cases, adversaries may be able to leverage Web Services such as Dropbox or OneDrive to copy files from one machine to another via shared, automatically synced folders.

Detection rules5

Rules on DetectionCode tagged with T1570.

Sigma4

Splunk1

RuleTypeRiskData source
Windows Lateral Tool Transfer RemComTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups19

Software27

Show 3 more

Campaigns9

Procedure examples55

Groups19

Used byProcedure example
GroupAgrius

Agrius downloaded some payloads for follow-on execution from legitimate filesharing services such as ufile.io and easyupload.io.

GroupAoqin Dragon

Aoqin Dragon has spread malware in target networks by copying modules to folders masquerading as removable devices.

GroupAPT32

APT32 has deployed tools after moving laterally using administrative accounts.

GroupAPT41

APT41 uses remote shares to move and remotely execute payloads during lateral movemement.

GroupBlackByte

BlackByte transfered tools such as Cobalt Strike and the AnyDesk remote access tool during operations using SMB shares.

GroupChimera

Chimera has copied tools between compromised hosts using SMB.

GroupEmber Bear

Ember Bear retrieves follow-on payloads direct from adversary-owned infrastructure for deployment on compromised hosts.

GroupFIN10

FIN10 has deployed Meterpreter stagers and SplinterRAT instances in the victim network after moving laterally.

View all 19 groups examples

Software27

Used byProcedure example
ToolBITSAdmin

BITSAdmin can be used to create BITS Jobs to upload and/or download files from SMB file servers.

MalwareBlackByte Ransomware

BlackByte Ransomware spreads itself laterally by writing the JavaScript launcher file to mapped shared folders.

MalwareBlackCat

BlackCat can replicate itself across connected servers via `psexec`.

Toolcmd

cmd can be used to copy files to/from a remotely connected internal system.

MalwareDustySky

DustySky searches for network drives and removable media and duplicates itself onto them.

MalwareEmotet

Emotet has copied itself to remote systems using the `service.exe` filename.

Toolesentutl

esentutl can be used to copy files to/from a remote share.

ToolExpand

Expand can be used to download or upload a file over a network share.

View all 27 software examples

Campaigns9

Used byProcedure example
Campaign2015 Ukraine Electric Power Attack

During the 2015 Ukraine Electric Power Attack, Sandworm Team moved their tools laterally within the corporate network and between the ICS and corporate network.

Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team used `move` to transfer files to a network share.

Campaign2022 Ukraine Electric Power Attack

During the 2022 Ukraine Electric Power Attack, Sandworm Team used a Group Policy Object (GPO) to copy CaddyWiper's executable `msserver.exe` from a staging server to a local hard drive before deployment.

Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries had placed the malicious payload on an accessible network share to facilitate propagation.

CampaignC0015

During C0015, the threat actors used WMI to load Cobalt Strike onto additional hosts within a compromised network.

CampaignC0018

During C0018, the threat actors transferred the SoftPerfect Network Scanner and other tools to machines in the network using AnyDesk and PDQ Deploy.

CampaignHomeLand Justice

During HomeLand Justice, threat actors initiated a process named Mellona.exe to spread the ROADSWEEP file encryptor and a persistence script to a list of internal machines.

CampaignOperation Wocao

During Operation Wocao, threat actors used SMB to copy files to and from target systems.

View all 9 campaigns examples

References2

  1. Dropbox Malware Sync Open source
    David Talbot. (2013, August 21). Dropbox and Similar Services Can Sync Malware. Retrieved May 31, 2023.
  2. Unit42 LockerGoga 2019 Open source
    Harbison, M. (2019, March 26). Born This Way? Origins of LockerGoga. Retrieved April 16, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.