RDP Hijacking

T1563.002

Sub-technique of T1563 Remote Service Session Hijacking.View on attack.mitre.org

About this technique

Adversaries may hijack a legitimate user’s remote desktop session to move laterally within an environment. Remote desktop is a common feature in operating systems. It allows a user to log into an interactive session with a system desktop graphical user interface on a remote system. Microsoft refers to its implementation of the Remote Desktop Protocol (RDP) as Remote Desktop Services (RDS).

Adversaries may perform RDP session hijacking which involves stealing a legitimate user's remote session. Typically, a user is notified when someone else is trying to steal their session. With System permissions and using Terminal Services Console, `c:\windows\system32\tscon.exe [session number to be stolen]`, an adversary can hijack a session without the need for credentials or prompts to the user. This can be done remotely or locally and with active or disconnected sessions. It can also lead to Remote System Discovery and Privilege Escalation by stealing a Domain Admin or higher privileged account session. All of this can be done by using native Windows commands, but it has also been added as a feature in red teaming tools.

Detection rules4

Rules on DetectionCode tagged with T1563.002.

Sigma2

RuleLevelLog source
Potential MSTSC Shadowing Activityhighwindows / process_creation
Suspicious RDP Redirect Using TSCONhighwindows / process_creation

Splunk2

RuleTypeRiskData source
Windows RDP Connection SuccessfulHuntingNULLWindows Event Log RemoteConnectionManager 1149
Windows Service Create with TsconTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups1

Software1

Campaigns0

None recorded.

Procedure examples2

Groups1

Used byProcedure example
GroupAxiom

Axiom has targeted victims with remote administration tools including RDP.

Software1

Used byProcedure example
MalwareWannaCry

WannaCry enumerates current remote desktop sessions and tries to execute the malware on each session.

References4

  1. Kali Redsnarf Open source
    NCC Group PLC. (2016, November 1). Kali Redsnarf. Retrieved December 11, 2017.
  2. RDP Hijacking Korznikov Open source
    Korznikov, A. (2017, March 17). Passwordless RDP Session Hijacking Feature All Windows versions. Retrieved December 11, 2017.
  3. RDP Hijacking Medium Open source
    Beaumont, K. (2017, March 19). RDP hijacking — how to hijack RDS and RemoteApp sessions transparently to move through an organisation. Retrieved December 11, 2017.
  4. TechNet Remote Desktop Services Open source
    Microsoft. (n.d.). Remote Desktop Services. Retrieved June 1, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.