Technique.View on attack.mitre.org
Adversaries may transfer tools or other files between systems in a compromised environment. Once brought into the victim environment (i.e., Ingress Tool Transfer) files may then be copied from one system to another to stage adversary tools or other files over the course of an operation.
Adversaries may copy files between internal victim systems to support lateral movement using inherent file sharing protocols such as file sharing over SMB/Windows Admin Shares to connected network shares or with authenticated connections via Remote Desktop Protocol.
Files can also be transferred using native or otherwise present tools on the victim system, such as scp, rsync, curl, sftp, and ftp. In some cases, adversaries may be able to leverage Web Services such as Dropbox or OneDrive to copy files from one machine to another via shared, automatically synced folders.
Rules on DetectionCode tagged with T1570.
| Rule | Level | Log source |
|---|---|---|
| Metasploit Or Impacket Service Installation Via SMB PsExec | high | windows / NULL |
| PSEXEC Remote Execution File Artefact | high | windows / file_event |
| Rundll32 Execution Without Parameters | high | windows / process_creation |
| Potentially Suspicious File Creation by OpenEDR's ITSMService | medium | windows / file_event |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Windows Lateral Tool Transfer RemCom | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Used by | Procedure example |
|---|---|
| GroupAgrius | Agrius downloaded some payloads for follow-on execution from legitimate filesharing services such as |
| GroupAoqin Dragon | Aoqin Dragon has spread malware in target networks by copying modules to folders masquerading as removable devices. |
| GroupAPT32 | APT32 has deployed tools after moving laterally using administrative accounts. |
| GroupAPT41 | APT41 uses remote shares to move and remotely execute payloads during lateral movemement. |
| GroupBlackByte | BlackByte transfered tools such as Cobalt Strike and the AnyDesk remote access tool during operations using SMB shares. |
| GroupChimera | Chimera has copied tools between compromised hosts using SMB. |
| GroupEmber Bear | Ember Bear retrieves follow-on payloads direct from adversary-owned infrastructure for deployment on compromised hosts. |
| GroupFIN10 | FIN10 has deployed Meterpreter stagers and SplinterRAT instances in the victim network after moving laterally. |
| Used by | Procedure example |
|---|---|
| ToolBITSAdmin | BITSAdmin can be used to create BITS Jobs to upload and/or download files from SMB file servers. |
| MalwareBlackByte Ransomware | BlackByte Ransomware spreads itself laterally by writing the JavaScript launcher file to mapped shared folders. |
| MalwareBlackCat | BlackCat can replicate itself across connected servers via `psexec`. |
| Toolcmd | cmd can be used to copy files to/from a remotely connected internal system. |
| MalwareDustySky | DustySky searches for network drives and removable media and duplicates itself onto them. |
| MalwareEmotet | Emotet has copied itself to remote systems using the `service.exe` filename. |
| Toolesentutl | esentutl can be used to copy files to/from a remote share. |
| ToolExpand | Expand can be used to download or upload a file over a network share. |
| Used by | Procedure example |
|---|---|
| Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team moved their tools laterally within the corporate network and between the ICS and corporate network. |
| Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team used `move` to transfer files to a network share. |
| Campaign2022 Ukraine Electric Power Attack | During the 2022 Ukraine Electric Power Attack, Sandworm Team used a Group Policy Object (GPO) to copy CaddyWiper's executable `msserver.exe` from a staging server to a local hard drive before deployment. |
| Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries had placed the malicious payload on an accessible network share to facilitate propagation. |
| CampaignC0015 | During C0015, the threat actors used WMI to load Cobalt Strike onto additional hosts within a compromised network. |
| CampaignC0018 | During C0018, the threat actors transferred the SoftPerfect Network Scanner and other tools to machines in the network using AnyDesk and PDQ Deploy. |
| CampaignHomeLand Justice | During HomeLand Justice, threat actors initiated a process named Mellona.exe to spread the ROADSWEEP file encryptor and a persistence script to a list of internal machines. |
| CampaignOperation Wocao | During Operation Wocao, threat actors used SMB to copy files to and from target systems. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.