Remote Desktop Protocol

T1021.001

Sub-technique of T1021 Remote Services.View on attack.mitre.org

About this technique

Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP). The adversary may then perform actions as the logged-on user.

Remote desktop is a common feature in operating systems. It allows a user to log into an interactive session with a system desktop graphical user interface on a remote system. Microsoft refers to its implementation of the Remote Desktop Protocol (RDP) as Remote Desktop Services (RDS).

Adversaries may connect to a remote system over RDP/RDS to expand access if the service is enabled and allows access to accounts with known credentials. Adversaries will likely use Credential Access techniques to acquire credentials to use with RDP. Adversaries may also use RDP in conjunction with the Accessibility Features or Terminal Services DLL for Persistence.

Detection rules33

Rules on DetectionCode tagged with T1021.001.

Sigma15

RuleLevelLog source
OpenCanary - RDP New Connection Attempthighopencanary / application
Outbound RDP Connections Over Non-Standard Toolshighwindows / network_connection
Potential Tampering With RDP Related Registry Keys Via Reg.EXEhighwindows / process_creation
Publicly Accessible RDP Servicehighzeek / NULL
RDP Login from Localhosthighwindows / NULL
RDP Over Reverse SSH Tunnelhighwindows / network_connection
RDP over Reverse SSH Tunnel WFPhighwindows / NULL
RDP to HTTP or HTTPS Target Portshighwindows / network_connection
Suspicious Plink Port Forwardinghighwindows / process_creation
Suspicious RDP Redirect Using TSCONhighwindows / process_creation
User Added to Remote Desktop Users Grouphighwindows / process_creation
Denied Access To Remote Desktopmediumwindows / NULL
New Remote Desktop Connection Initiated Via Mstsc.EXEmediumwindows / process_creation
Port Forwarding Activity Via SSH.EXEmediumwindows / process_creation
RDP Enable or Disable via Win32_TerminalServiceSetting WMI Classmediumwindows / process_creation

Splunk18

RuleTypeRiskData source
Allow Inbound Traffic By Firewall Rule RegistryTTPNULLSysmon EventID 13
Allow Inbound Traffic In Firewall RuleTTPNULLPowershell Script Block Logging 4104
Remote Desktop Network TrafficAnomalyNULLZeek Conn
Remote Desktop Process Running On SystemHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Default RDP File CreationAnomalyNULLSysmon EventID 11
Windows Default RDP File Creation By Non MSTSC ProcessAnomalyNULLSysmon EventID 1 AND Sysmon EventID 11
Windows Default Rdp File UnhiddenAnomalyNULLSysmon EventID 1
Windows MSTSC RDP CommandlineAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Process Execution From RDP ShareAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows RDP Bitmap Cache File CreationAnomalyNULLSysmon EventID 11
Windows RDP Client Launched with Admin SessionAnomalyNULLSysmon EventID 1
Windows RDP File ExecutionTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows RDP Login Session Was EstablishedAnomalyNULLWindows Event Log Security 4624
Windows RDP Server Registry Entry CreatedAnomalyNULLSysmon EventID 13
Windows Remote Service Rdpwinst Tool ExecutionTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups37

Show 13 more

Software17

Campaigns9

Procedure examples63

Groups37

Used byProcedure example
GroupAgrius

Agrius tunnels RDP traffic through deployed web shells to access victim environments via compromised accounts. Agrius used the Plink tool to tunnel RDP connections for remote access and lateral movement in victim environments.

GroupAkira

Akira has used RDP for lateral movement.

GroupAPT1

The APT1 group is known to have used RDP during operations.

GroupAPT3

APT3 enables the Remote Desktop Protocol for persistence. APT3 has also interacted with compromised systems to browse and copy files through RDP sessions.

GroupAPT39

APT39 has been seen using RDP for lateral movement and persistence, in some cases employing the rdpwinst tool for mangement of multiple sessions.

GroupAPT41

APT41 used RDP for lateral movement. APT41 used NATBypass to expose local RDP ports on compromised systems to the Internet.

GroupAPT5

APT5 has moved laterally throughout victim environments using RDP.

GroupAquatic Panda

Aquatic Panda leveraged stolen credentials to move laterally via RDP in victim environments.

View all 37 groups examples

Software17

Used byProcedure example
MalwareCarbanak

Carbanak enables concurrent Remote Desktop Protocol (RDP) sessions.

MalwareCobalt Strike

Cobalt Strike can start a VNC-based remote desktop server and tunnel the connection through the already established C2 channel.

MalwareDarkComet

DarkComet can open an active screen of the victim’s machine and take control of the mouse and keyboard.

ToolImminent Monitor

Imminent Monitor has a module for performing remote desktop access.

MalwarejRAT

jRAT can support RDP control.

ToolKoadic

Koadic can enable remote desktop on the victim's machine.

MalwarenjRAT

njRAT has a module for performing remote desktop access.

ToolPupy

Pupy can enable/disable RDP connection and can start a remote desktop session using a browser web socket client.

View all 17 software examples

Campaigns9

Used byProcedure example
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, adversaries utilized RDP to log into jump hosts and then moved laterally to other victim devices to include a domain controller.

CampaignAPT28 Nearest Neighbor Campaign

During APT28 Nearest Neighbor Campaign, APT28 used RDP for lateral movement.

CampaignC0015

During C0015, the threat actors used RDP to access specific network hosts of interest.

CampaignC0018

During C0018, the threat actors opened a variety of ports to establish RDP connections, including ports 28035, 32467, 41578, and 46892.

CampaignC0032

During the C0032 campaign, TEMP.Veles utilized RDP throughout an operation.

CampaignCutting Edge

During Cutting Edge, threat actors used RDP with compromised credentials for lateral movement.

CampaignHomeLand Justice

During HomeLand Justice, threat actors primarily used RDP for lateral movement in the victim environment.

CampaignOperation Digital Eye

During Operation Digital Eye, threat actors moved laterally using RDP.

View all 9 campaigns examples

References2

  1. Alperovitch Malware Open source
    Alperovitch, D. (2014, October 31). Malware-Free Intrusions. Retrieved November 17, 2024.
  2. TechNet Remote Desktop Services Open source
    Microsoft. (n.d.). Remote Desktop Services. Retrieved June 1, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.