T1021.004: T1021.004
Essential information
- MITRE technique ID
T1021.004- Confidence
- 100/100
- Revoked
- No
- Published
- 11/02/2020 19:27
- Modified
- 27/03/2026 01:09
- Author / Source
- The MITRE Corporation
Aliases
SSH
Platforms
macos linux ESXi
Description
Kill chain phases
| Kill chain | Phase |
|---|---|
| mitre-attack | lateral-movement |
Marking (TLP)
TLP:GREEN Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Intrusion sets, malware, reports, vulnerabilities, indicators and other entities linked to this technique.
Intrusion sets (APT) (53)
-
UNC3886 usesThe MITRE Corporation Confidence 100
[UNC3886](https://attack.mitre.org/groups/G1048) is a China-nexus cyberespionage group that has been active since at least 2022, targeting defense, technology, and telecommunication organizations located in the United States and the Asia-Pacific-Japan…
First seen 01/01/1970 · Last seen 16/11/5138 · -
CL-STA-1132 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Outlaw usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
GCMAN usesThe MITRE Corporation Confidence 100
[GCMAN](https://attack.mitre.org/groups/G0036) is a threat group that focuses on targeting banks for the purpose of transferring money to e-currency services. (Citation: Securelist GCMAN)
First seen 01/01/1970 · Last seen 16/11/5138 · -
The MITRE Corporation Confidence 100
[APT28](https://attack.mitre.org/groups/G0007) is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165.(Citation: NSA/FBI Drovorub…
First seen 01/01/1970 · Last seen 16/11/5138 · -
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Kyber usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
The MITRE Corporation Confidence 100
[menuPass](https://attack.mitre.org/groups/G0045) is a threat group that has been active since at least 2006. Individual members of [menuPass](https://attack.mitre.org/groups/G0045) are known to have acted in association with the Chinese Ministry…
First seen 01/01/1970 · Last seen 16/11/5138 · -
The MITRE Corporation Confidence 100
[OilRig](https://attack.mitre.org/groups/G0049) is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a variety of sectors, including…
First seen 01/01/1970 · Last seen 16/11/5138 · -
vpmdhaj usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
TeamTNT usesThe MITRE Corporation Confidence 100
[TeamTNT](https://attack.mitre.org/groups/G0139) is a threat group that has primarily targeted cloud and containerized environments. The group as been active since at least October 2019 and has mainly focused its…
First seen 01/01/1970 · Last seen 16/11/5138 · -
The MITRE Corporation Confidence 100
[Magic Hound](https://attack.mitre.org/groups/G0059) is an Iranian-sponsored threat group that conducts long term, resource-intensive cyber espionage operations, likely on behalf of the Islamic Revolutionary Guard Corps. They have targeted European,…
First seen 01/01/1970 · Last seen 16/11/5138 ·
Malware (73)
-
UPDTAE usesFamily
-
zylogin usesFamily
-
RushDrop usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Monster usesFamily
-
BUSYBOX usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
EarthWorm usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
XWorm usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
PowerShort usesFamily
-
ReverseSocks5 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
httd usesFamily
-
Powertrash usesFamily
-
Dota usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Reports (50)
-
12 CVEs 20 MITREs 2 Malwares 4 Observables 1 APT
-
AlienVault Confidence 100 20 MITREs 7 IOCs 7 Observables 1 APT
-
AlienVault Confidence 100 21 MITREs 1 Malware 8 IOCs 8 Observables 1 APT
-
19 MITREs 10 Observables 1 APT
-
19 MITREs 1 Malware 3 Observables 1 APT
-
2 CVEs 19 MITREs 2 Malwares 14 Observables 1 APT
-
2 CVEs 20 MITREs 10 Malwares 5 Observables 1 APT
-
2 CVEs 21 MITREs 2 Malwares 12 Observables
-
16 MITREs 10 Malwares 1 Observable
-
12 MITREs 2 Malwares 7 Observables 1 APT
-
20 MITREs 2 Malwares 5 Observables 1 APT
-
9 MITREs 1 Malware 16 Observables
Vulnerabilities (CVE) (78)
Rejected reason: This CVE is a duplicate of CVE-2025-55182.
- Published
- 20/12/2025
- Modified
- 21/12/2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before …
- Attack vector
- Network
- Published
- 04/04/2025
- Modified
- 21/12/2025
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and …
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 11/06/2026
- Modified
- 12/06/2026
NVIDIA NeMo library for all platforms contains a vulnerability in the model loading component, where an attacker could cause code injection by …
- Attack vector
- LOCAL
- Published
- 13/08/2025
- Modified
- 17/04/2026
Spring Cloud Gateway applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured.
- Published
- 16/05/2022
- Modified
- 20/12/2025
May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was …
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 14/05/2026
- Modified
- 18/06/2026
Palo Alto Networks PAN-OS GlobalProtect feature contains a command injection vulnerability that allows an unauthenticated attacker to execute commands with root privileges …
- Attack vector
- Network
- Published
- 12/04/2024
- Modified
- 21/12/2025
Gogs is an open source self-hosted Git service. A malicious user is able to write a file to an arbitrary path on …
- Published
- 23/12/2024
- Modified
- 24/12/2024
Fortinet FortiFone, FortiVoice, FortiNDR and FortiMail contain a stack-based overflow vulnerability that may allow a remote unauthenticated attacker to execute arbitrary code …
- Attack vector
- Network
- Published
- 14/05/2025
- Modified
- 14/01/2026
A vulnerability was found in TBK DVR-4104 and DVR-4216 up to 20240412 and classified as critical. This issue affects some unknown processing …
- Attack vector
- NETWORK
- Published
- 13/04/2024
- Modified
- 21/12/2025
Teclib GLPI contains a remote code execution vulnerability in the third-party library, htmlawed.
- Attack vector
- Network
- Published
- 07/03/2023
- Modified
- 04/06/2026
vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway that if exploited an attacker could use to allow unintended commands or code …
- Published
- 11/06/2024
- Modified
- 11/06/2024
Campaign (1)
-
Leviathan Australian Intrusions uses
Course Of Action (1)
-
Disable or Remove Feature or Program mitigates
Tool (1)
-
Empire usesThe MITRE Corporation Confidence 100
[Empire](https://attack.mitre.org/software/S0363) is an open-source, cross-platform remote administration and post-exploitation framework that is publicly available on GitHub. While the tool itself is primarily written in Python, the post-exploitation agents…