216.73.216.6

T1219.002: Remote Desktop Software

View on MITRE ATT&CK The MITRE Corporation · Published 24/03/2025 23:24 · Modified 27/03/2026 01:12

Essential information

MITRE technique ID
T1219.002
Confidence
100/100
Revoked
No
Published
24/03/2025 23:24
Modified
27/03/2026 01:12
Author / Source
The MITRE Corporation

Platforms

windows macos linux

Description

An adversary may use legitimate desktop support software to establish an interactive command and control channel to target systems within networks. Desktop support software provides a graphical interface for remotely controlling another computer, transmitting the display output, keyboard input, and mouse control between devices using various protocols. Desktop support software, such as `VNC`, `Team Viewer`, `AnyDesk`, `ScreenConnect`, `LogMein`, `AmmyyAdmin`, and other remote monitoring and management (RMM) tools, are commonly used as legitimate technical support software and may be allowed by application control within a target environment.(Citation: Symantec Living off the Land)(Citation: CrowdStrike 2015 Global Threat Report)(Citation: CrySyS Blog TeamSpy) Remote access modules/features may also exist as part of otherwise existing software such as Zoom or Google Chrome’s Remote Desktop.(Citation: Google Chrome Remote Desktop)(Citation: Chrome Remote Desktop)

Kill chain phases

Kill chainPhase
mitre-attack command-and-control

Marking (TLP)

Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.

External references