Remote Access Tools

T1219

Technique with 3 sub-techniques.View on attack.mitre.org

About this technique

An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network. Remote access tools create a session between two trusted hosts through a graphical interface, a command line interaction, a protocol tunnel via development or management software, or hardware-level access such as KVM (Keyboard, Video, Mouse) over IP solutions. Desktop support software (usually graphical interface) and remote management software (typically command line interface) allow a user to control a computer remotely as if they are a local user inheriting the user or software permissions. This software is commonly used for troubleshooting, software installation, and system management. Adversaries may similarly abuse response features included in EDR and other defensive tools that enable remote access.

Remote access tools may be installed and used post-compromise as an alternate communications channel for redundant access or to establish an interactive remote desktop session with the target system. It may also be used as a malware component to establish a reverse connection or back-connect to a service or adversary-controlled system.

Installation of many remote access tools may also include persistence (e.g., the software's installation routine creates a Windows Service). Remote access modules/features may also exist as part of otherwise existing software (e.g., Google Chrome’s Remote Desktop).

Detection rules65

Rules on DetectionCode tagged with T1219 or one of its sub-techniques.

Sigma49

RuleLevelLog sourceTechnique
Antivirus - APT Malware SignaturecriticalNULL / antivirusT1219.002
Antivirus - Exploitation Framework SignaturecriticalNULL / antivirusT1219.002
Antivirus - Remote Access Tools SignaturecriticalNULL / antivirusT1219.002
HackTool - Inveigh Execution Artefactscriticalwindows / file_eventT1219.002
Atera Agent Installationhighwindows / NULLT1219.002
HackTool - RemoteKrbRelay SMB Relay Secrets Dump Module Indicatorshighwindows / file_eventT1219.002
Hijack Legit RDP Session to Move Laterallyhighwindows / file_eventT1219.002
Remote Access Tool - Anydesk Execution From Suspicious Folderhighwindows / process_creationT1219.002
Remote Access Tool - AnyDesk Silent Installationhighwindows / process_creationT1219.002
Remote Access Tool - Renamed MeshAgent Execution - MacOShighmacos / process_creationT1219.002
Remote Access Tool - Renamed MeshAgent Execution - Windowshighwindows / process_creationT1219.002
Renamed Visual Studio Code Tunnel Executionhighwindows / process_creationT1219
Suspicious Binary Writes Via AnyDeskhighwindows / file_eventT1219.002
Suspicious Mstsc.EXE Execution With Local RDP Filehighwindows / process_creationT1219.002
Suspicious TSCON Start as SYSTEMhighwindows / process_creationT1219.002

Splunk16

RuleTypeRiskData sourceTechnique
Cisco Secure Firewall - Communication Over Suspicious PortsAnomalyNULLCisco Secure Firewall Threat Defense Connection EventT1219
Cisco Secure Firewall - Remote Access Software Usage TrafficAnomalyNULLCisco Secure Firewall Threat Defense Connection EventT1219
Detect Remote Access Software Usage DNSAnomalyNULLSysmon EventID 22T1219
Detect Remote Access Software Usage FileAnomalyNULLSysmon EventID 11T1219
Detect Remote Access Software Usage FileInfoAnomalyNULLSysmon EventID 1T1219
Detect Remote Access Software Usage ProcessAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1219
Detect Remote Access Software Usage RegistryAnomalyNULLSysmon EventID 13T1219
Detect Remote Access Software Usage TrafficAnomalyNULLPalo Alto Network TrafficT1219
Detect Remote Access Software Usage URLAnomalyNULLPalo Alto Network ThreatT1219
HTTP RMM User AgentAnomalyNULLSuricataT1219
Windows Level RMM PowerShell Script InstallerAnomalyNULLPowershell Script Block Logging 4104T1219
Windows Level RMM Watchdog Task CreatedAnomalyNULLWindows Event Log Security 4698T1219
Windows Remote Access Software BRC4 Loaded DllAnomalyNULLSysmon EventID 7T1219
Windows Remote Access Software HuntHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1219
Windows Remote Access Software RMS RegistryTTPNULLSysmon EventID 13T1219

Sub-techniques3

IDNameExamples
T1219.001IDE Tunneling3
T1219.002Remote Desktop Software15
T1219.003Remote Access Hardware0

Groups13

Software7

Campaigns2

Procedure examples22

Groups13

Used byProcedure example
GroupAkira

Akira uses legitimate utilities such as AnyDesk and PuTTy for maintaining remote access to victim environments.

GroupBlackByte

BlackByte has used tools such as AnyDesk in victim environments.

GroupCarbanak

Carbanak used legitimate programs such as AmmyyAdmin and Team Viewer for remote interactive C2 to target systems.

GroupCobalt Group

Cobalt Group used the Ammyy Admin tool as well as TeamViewer for remote access, including to preserve remote access if a Cobalt Strike module was lost.

GroupDarkVishnya

DarkVishnya used DameWare Mini Remote Control for lateral movement.

GroupFIN7

FIN7 has utilized the remote management tool Atera to download malware to a compromised system.

GroupGOLD SOUTHFIELD

GOLD SOUTHFIELD has used the cloud-based remote management and monitoring tool "ConnectWise Control" to deploy REvil.

GroupINC Ransom

INC Ransom has used AnyDesk and PuTTY on compromised systems.

View all 13 groups examples

Software7

Used byProcedure example
MalwareCarbanak

Carbanak has a plugin for VNC and Ammyy Admin Tool.

MalwareDridex

Dridex contains a module for VNC.

MalwareEgregor

Egregor has checked for the LogMein event log in an attempt to encrypt files in remote machines.

MalwareHildegard

Hildegard has established tmate sessions for C2 communications.

MalwareInvisibleFerret

InvisibleFerret has utilized remote access software including AnyDesk client through the “adc” module. InvisibleFerret has also downloaded the AnyDesk client should it not already exist on the compromised host by searching for `C:/Program Files(x86)/AnyDesk/AnyDesk.exe`.

MalwareRTM

RTM has the capability to download a VNC module from command and control (C2).

MalwareTrickBot

TrickBot uses vncDll module to remote control the victim machine.

Campaigns2

Used byProcedure example
CampaignNight Dragon

During Night Dragon, threat actors used several remote administration tools as persistent infiltration channels.

CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace used remote access tools including PuTTY.

References5

  1. Chrome Remote Desktop Open source
    Huntress. (n.d.). Retrieved March 14, 2024.
  2. CrowdStrike 2015 Global Threat Report Open source
    CrowdStrike Intelligence. (2016). 2015 Global Threat Report. Retrieved April 11, 2018.
  3. CrySyS Blog TeamSpy Open source
    CrySyS Lab. (2013, March 20). TeamSpy – Obshie manevri. Ispolzovat’ tolko s razreshenija S-a. Retrieved April 11, 2018.
  4. Google Chrome Remote Desktop Open source
    Google. (n.d.). Retrieved March 14, 2024.
  5. Symantec Living off the Land Open source
    Wueest, C., Anand, H. (2017, July). Living off the land and fileless attack techniques. Retrieved April 10, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.