Sub-technique of T1021 Remote Services.View on attack.mitre.org
Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB). The adversary may then perform actions as the logged-on user.
SMB is a file, printer, and serial port sharing protocol for Windows machines on the same network or domain. Adversaries may use SMB to interact with file shares, allowing them to move laterally throughout a network. Linux and macOS implementations of SMB typically use Samba.
Windows systems have hidden network shares that are accessible only to administrators and provide the ability for remote file copy and other administrative functions. Example network shares include `C$`, `ADMIN$`, and `IPC$`. Adversaries may use this technique in conjunction with administrator-level Valid Accounts to remotely access a networked system over SMB, to interact with systems using remote procedure calls (RPCs), transfer files, and run transferred binaries through remote Execution. Example execution techniques that rely on authenticated sessions over SMB/RPC are Scheduled Task/Job, Service Execution, and Windows Management Instrumentation. Adversaries can also use NTLM hashes to access administrator shares on systems with Pass the Hash and certain configuration and patch levels.
Rules on DetectionCode tagged with T1021.002.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Detect PsExec With accepteula Flag | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Executable File Written in Administrative SMB Share | TTP | NULL | Windows Event Log Security 5145 |
| Impacket Lateral Movement Commandline Parameters | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Impacket Lateral Movement smbexec CommandLine Parameters | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Impacket Lateral Movement WMIExec Commandline Parameters | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| SMB Traffic Spike | Anomaly | NULL | |
| SMB Traffic Spike - MLTK | Anomaly | NULL | |
| Windows Alternate Data Stream Created Over Local Share | Anomaly | NULL | Windows Event Log Security 5145 |
| Windows PUA Named Pipe | Anomaly | NULL | Sysmon EventID 17, Sysmon EventID 18 |
| Windows RMM Named Pipe | Anomaly | NULL | Sysmon EventID 17, Sysmon EventID 18 |
| Windows Special Privileged Logon On Multiple Hosts | TTP | NULL | Windows Event Log Security 4672 |
| Windows Suspicious C2 Named Pipe | TTP | NULL | Sysmon EventID 17, Sysmon EventID 18 |
| Windows Suspicious Named Pipe | TTP | NULL | Sysmon EventID 17, Sysmon EventID 18 |
| Windows Theme File Creation in Unusual Location | Anomaly | NULL | Sysmon EventID 11 |
| Used by | Procedure example |
|---|---|
| GroupAPT28 | APT28 has mapped network drives using Net and administrator credentials. |
| GroupAPT3 | APT3 will copy files over to Windows Admin Shares (like ADMIN$) as part of lateral movement. |
| GroupAPT32 | APT32 used Net to use Windows' hidden network shares to copy their tools to remote machines for execution. |
| GroupAPT39 | APT39 has used SMB for lateral movement. |
| GroupAPT41 | APT41 has transferred implant files using Windows Admin Shares and the Server Message Block (SMB) protocol, then executes files through Windows Management Instrumentation (WMI). |
| GroupAquatic Panda | Aquatic Panda used remote shares to enable lateral movement in victim environments. |
| GroupBlackByte | BlackByte used SMB file shares to distribute payloads throughout victim networks, including BlackByte ransomware variants during wormable operations. |
| GroupBlue Mockingbird | Blue Mockingbird has used Windows Explorer to manually copy malicious files to remote hosts over SMB. |
| Used by | Procedure example |
|---|---|
| MalwareAnchor | Anchor can support windows execution via SMB shares. |
| MalwareBlackByte Ransomware | BlackByte Ransomware uses mapped shared folders to transfer ransomware payloads via SMB. |
| MalwareBlackEnergy | BlackEnergy has run a plug-in on a victim to spread through the local network by using PsExec and accessing admin shares. |
| ToolBrute Ratel C4 | Brute Ratel C4 has the ability to use SMB to pivot in compromised networks. |
| MalwareCobalt Strike | Cobalt Strike can use Window admin shares (C$ and ADMIN$) for lateral movement. |
| MalwareConficker | Conficker variants spread through NetBIOS share propagation. |
| MalwareConti | Conti can spread via SMB and encrypts files on different hosts, potentially compromising an entire network. |
| MalwareDiavol | Diavol can spread throughout a network via SMB prior to encryption. |
| Used by | Procedure example |
|---|---|
| Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team utilized `net use` to connect to network shares. |
| CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 leveraged SMB to transfer files and move laterally. |
| CampaignCutting Edge | During Cutting Edge, threat actors moved laterally using compromised credentials to connect to internal Windows systems with SMB. |
| CampaignHomeLand Justice | During HomeLand Justice, threat actors used SMB for lateral movement. |
| CampaignLeviathan Australian Intrusions | Leviathan used remote shares to move laterally through victim networks during Leviathan Australian Intrusions. |
| CampaignOperation MidnightEclipse | During Operation MidnightEclipse, threat actors used SMB to pivot internally in victim networks. |
| CampaignOperation Wocao | During Operation Wocao, threat actors used Impacket's smbexec.py as well as accessing the C$ and IPC$ shares to move laterally. |
| CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used administrative accounts to connect over SMB to targeted users. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.