Remote Desktop Software

T1219.002

Sub-technique of T1219 Remote Access Tools.View on attack.mitre.org

About this technique

An adversary may use legitimate desktop support software to establish an interactive command and control channel to target systems within networks. Desktop support software provides a graphical interface for remotely controlling another computer, transmitting the display output, keyboard input, and mouse control between devices using various protocols. Desktop support software, such as `VNC`, `Team Viewer`, `AnyDesk`, `ScreenConnect`, `LogMein`, `AmmyyAdmin`, and other remote monitoring and management (RMM) tools, are commonly used as legitimate technical support software and may be allowed by application control within a target environment.

Remote access modules/features may also exist as part of otherwise existing software such as Zoom or Google Chrome’s Remote Desktop.

Detection rules43

Rules on DetectionCode tagged with T1219.002.

Sigma43

RuleLevelLog source
Antivirus - APT Malware SignaturecriticalNULL / antivirus
Antivirus - Exploitation Framework SignaturecriticalNULL / antivirus
Antivirus - Remote Access Tools SignaturecriticalNULL / antivirus
HackTool - Inveigh Execution Artefactscriticalwindows / file_event
Atera Agent Installationhighwindows / NULL
HackTool - RemoteKrbRelay SMB Relay Secrets Dump Module Indicatorshighwindows / file_event
Hijack Legit RDP Session to Move Laterallyhighwindows / file_event
Remote Access Tool - Anydesk Execution From Suspicious Folderhighwindows / process_creation
Remote Access Tool - AnyDesk Silent Installationhighwindows / process_creation
Remote Access Tool - Renamed MeshAgent Execution - MacOShighmacos / process_creation
Remote Access Tool - Renamed MeshAgent Execution - Windowshighwindows / process_creation
Suspicious Binary Writes Via AnyDeskhighwindows / file_event
Suspicious Mstsc.EXE Execution With Local RDP Filehighwindows / process_creation
Suspicious TSCON Start as SYSTEMhighwindows / process_creation
Anydesk Temporary Artefactmediumwindows / file_event

Splunk0

No Splunk rules are mapped to this technique yet.

Groups11

Software1

Campaigns3

Procedure examples15

Groups11

Used byProcedure example
GroupContagious Interview

Contagious Interview has downloaded remote management and monitoring software such as “AnyDesk” for post compromise activities.

GroupEvilnum

EVILNUM has used the malware variant, TerraTV, to run a legitimate TeamViewer application to connect to compromised machines.

GroupKimsuky

Kimsuky has used a modified TeamViewer client as a command and control channel.

GroupMuddyWater

MuddyWater has leveraged RMM solutions including ScreenConnect, AteraAgent, SimpleHelp, Action1, Level, and PDQ to facilitate follow-on actions within compromised hosts to include data exfiltration.

GroupMustang Panda

Mustang Panda has installed TeamViewer on targeted systems.

GroupRTM

RTM has used a modified version of TeamViewer and Remote Utilities for remote access.

GroupScattered Spider

In addition to directing victims to run remote software, Scattered Spider members themselves also deploy RMM software including TeamViewer, AnyDesk, LogMeIn, ngrok, and ConnectWise to establish persistence on the compromised network.

GroupStorm-0501

Storm-0501 has used legitimate remote monitoring and management (RMM) tools including AnyDesk, NinjaOne, and Level.io.

View all 11 groups examples

Software1

Used byProcedure example
MalwareQilin

Qilin can use the Splashtop remote management service (SRManager.exe) to execute the Linux ransomware binary directly on Windows systems.

Campaigns3

Used byProcedure example
CampaignC0015

During C0015, the threat actors installed the AnyDesk remote desktop application onto the compromised network.

CampaignC0018

During C0018, the threat actors used AnyDesk to transfer tools between systems.

CampaignC0027

During C0027, Scattered Spider directed victims to run remote monitoring and management (RMM) tools.

References5

  1. Chrome Remote Desktop Open source
    Huntress. (n.d.). Retrieved March 14, 2024.
  2. CrowdStrike 2015 Global Threat Report Open source
    CrowdStrike Intelligence. (2016). 2015 Global Threat Report. Retrieved April 11, 2018.
  3. CrySyS Blog TeamSpy Open source
    CrySyS Lab. (2013, March 20). TeamSpy – Obshie manevri. Ispolzovat’ tolko s razreshenija S-a. Retrieved April 11, 2018.
  4. Google Chrome Remote Desktop Open source
    Google. (n.d.). Retrieved March 14, 2024.
  5. Symantec Living off the Land Open source
    Wueest, C., Anand, H. (2017, July). Living off the land and fileless attack techniques. Retrieved April 10, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.