Activity timeline
T1021 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 133 reports, and 364 of the 364 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1021 Remote Services is catalogued by MITRE ATT&CK under the Lateral Movement tactic in the Enterprise matrix. Threadlinqs maps 364 of 2623 tracked threats (13.9%) to it; by severity that is 171 critical, 160 high, 24 medium, 2 low.
Threats that use T1021 most often also use T1059 Command and Scripting Interpreter (273 threats), T1190 Exploit Public-Facing Application (240 threats), T1071 Application Layer Protocol (222 threats), T1078 Valid Accounts (216 threats), T1005 Data from Local System (189 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
131 tracked threat actors appear in the threats that use T1021; the most frequent are MuddyWater (7), Static Tundra (7), TeamPCP (7), LockBit (6), Qilin (6).
Mitigations
MITRE ATT&CK lists 6 mitigations for T1021.
Data sources
Telemetry that can reveal T1021, per MITRE ATT&CK.
- Command — Command Execution
- Logon Session — Logon Session Creation
- Module — Module Load
- Network Share — Network Share Access
- Network Traffic — Network Connection Creation, Network Traffic Flow
- Process — Process Creation
- WMI — WMI Creation
Threat actors using it
Tracked threats
The 30 most recent of 364 tracked threats that use T1021.
- CISA adds two Zammad vulnerabilities to KEV: CVE-2026-102489 (session fixation to RCE) and CVE-2026-102490…critical
- Storm-3168 (JADEPUFFER): Agentic-Driven Destructive Cloud Attacks Against Azure via Compromised Service…critical
- Cyberattack Disrupts Dyfed-Powys Police Systems in Wales, Staff Data Possibly Compromisedmedium
- Ransomware Attack Disrupts IT Systems and Services in Ellis County, Kansashigh
- Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH Against India and…high
- Rehub: Russian-Language Ransomware-as-a-Service Marketplace Absorbing RAMP's Displaced Operatorsmedium
- VSS Abuse: Attackers Weaponize Windows Volume Shadow Copy Service for Ransomware Prep and Credential Thefthigh
- CVE-2025-25249: Fortinet Heap-Based Buffer Overflow Exploited to Deploy PivotC2 RAT on FortiGate Devicescritical
- CVE-2026-86218 — Unauthenticated Pre-Auth Remote Code Execution in N-able N-central (Active Exploitation…critical
- Hyadina Rebrands Beast Ransomware as 'GodDamn' and Uses PoisonX Signed Kernel Driver to Disable Endpoint…critical
- Microsoft September 2026 Patch Tuesday — 999 CVEs, 3 actively exploited zero-days (CVE-2026-85880…critical
- September 2026 Microsoft Patch Tuesday — Record 966+ Vulnerabilities with Two Actively Exploited Zero-Days…critical
- Ivanti September 2026 Patch Batch: 10 CVEs Across EPMM, Neurons for ITSM, and Sentry (CVE-2026-12744/12745…critical
- Telerik UI for ASP.NET AJAX — Padding Oracle Chained to Unauthenticated Deserialization RCE…high
- DragonForce Ransomware Attack on RubberMill, Inc. — ~340GB Data Exfiltration Including PII, Credentials, CAD…critical
- Vexy Ransomware hits Mega Velocity — 46.68 GB exfiltrated, double extortionhigh
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication (MikroTrick)critical
- Chinese-Speaking Operator "Nie" Uses SecFlow AI Orchestration Framework (Claude, Qwen, DeepSeek) and GLUTTON…high
- ORB Networks and Nation-State CNI Targeting: Destructive Wiper Attack on Polish Energy Infrastructure via…high
- HPE Patches Critical ArubaOS-CX Buffer Overflow (CVE-2026-73749) Enabling Unauthenticated Remote Code…critical
- Mustang Panda Targets India's Government and Energy Sectors with SHARDLOADER, MINIRECON, and ZOHOMURKhigh
- Aur0ra Ransomware Group: Xray-core C2 Tunneling, Aggressive Email Bombing, and Log-Wiping Double-Extortion…high
- Chaos Ransomware Claims MacAllister (macallister.com) — 75GB Data Exfiltration Claimed, Leadership Refused…high
- PaperCut NG/MF Application Server Zero-Day: Unauthenticated RCE Under Active Exploitation, No CVE Assignedcritical
- PaperCut NG/MF Print Management Software Under Active Exploitation of Unpatched Vulnerabilityhigh
- SLEEPWALKER: Passive-Trigger Windows Backdoor Masquerading as dpapi.dll via ERAAgent.exe Side-Loadingmedium
- Dark Caracal Expands Espionage Arsenal with GoCaracal Framework and AsioGate Backdoorhigh
- Edge Infrastructure Under Siege: Tenable and SentinelOne Datasets Reveal Convergent Nation-State and…high
- JA4H Fingerprinting Detects Sliver C2 Deployed via Chained PAN-OS CVE-2024-0012/CVE-2024-9474 Exploitationhigh
- 2026 Ransomware Surge Targeting US Organizations: Identity-First Compromise, BYOVD, and Living-Off-the-Cloud…high
Detection coverage
Threadlinqs maintains 204 detection rules mapped to T1021 (SPL 64, KQL 75, Sigma 65). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1021.001 Remote Desktop Protocol — 103 tracked threats
- T1021.002 SMB/Windows Admin Shares — 90 tracked threats
- T1021.003 Distributed Component Object Model — 3 tracked threats
- T1021.004 SSH — 63 tracked threats
- T1021.005 VNC — 11 tracked threats
- T1021.006 Windows Remote Management — 12 tracked threats
- T1021.007 Cloud Services — 6 tracked threats
- T1021.008 Direct Cloud VM Connections — 0 tracked threats