Activity timeline
T1021.001 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 34 reports, and 103 of the 103 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1021.001 Remote Desktop Protocol is catalogued by MITRE ATT&CK under the Lateral Movement tactic in the Enterprise matrix, as a sub-technique of T1021 Remote Services. Threadlinqs maps 103 of 2623 tracked threats (3.9%) to it; by severity that is 33 critical, 58 high, 11 medium.
Threats that use T1021.001 most often also use T1059.001 PowerShell (55 threats), T1190 Exploit Public-Facing Application (55 threats), T1133 External Remote Services (53 threats), T1685 Disable or Modify Tools (53 threats), T1071.001 Web Protocols (52 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
64 tracked threat actors appear in the threats that use T1021.001; the most frequent are Qilin (6), Akira (5), Storm-1567 (4), APT38 (3), GhostEmperor (3).
Mitigations
MITRE ATT&CK lists 8 mitigations for T1021.001.
Data sources
Telemetry that can reveal T1021.001, per MITRE ATT&CK.
- Logon Session — Logon Session Creation, Logon Session Metadata
- Network Traffic — Network Connection Creation, Network Traffic Flow
- Process — Process Creation
Threat actors using it
Tracked threats
The 30 most recent of 103 tracked threats that use T1021.001.
- Microsoft Tracks Storm-2570 Ransomware Affiliate Behind Qilin, DragonForce, Anubis, and BERT Deploymentshigh
- Ryuk Ransomware Initial Access Operator Karen Vardanyan ("Maneeken") Sentenced to 24 Months in U.S. Federal…medium
- NightEagle (APT-Q-95) Deploys GhostContainer Backdoor on Exchange, Exploits BlueKeep (CVE-2019-0708) and…critical
- Ransomware Incidents Surge 4.7% in Japan H1 2026: The Gentlemen and Qilin Lead, AI-Assisted Tooling Observedhigh
- Team Cymru Infrastructure Analysis: Seven Active Ransomware Gangs (Akira, DragonForce, Clop, MedusaLocker…high
- Adobe Campaign Classic Critical OS Command Injection (CVE-2026-82004, APSB26-142, CVSS 10.0)critical
- Microsoft September 2026 Patch Tuesday — 999 CVEs, 3 actively exploited zero-days (CVE-2026-85880…critical
- Rhysida Ransomware Campaign Targeting German Public Administration (Stuttgart and Berlin, 2026)critical
- DaVita Settles $15M Class Action Over Interlock Ransomware Breach Affecting 2.7M Patientshigh
- The Gentlemen RaaS (GOLD SHERWOOD / hastalamuerte): FortiGate/VPN Intrusion Chain, GentleKiller BYOVD EDR…critical
- BREEZE COMET (ex-UNC5669) Targets Brazilian Financial Infrastructure with AI-Assisted Custom Malware Suitecritical
- Rhysida Ransomware Claims Berlin State Government Breach Ahead of September Electionhigh
- Qilin Ransomware Gang Claims Breach of US ATF; Agency Confirms 'Major Incident' on Isolated Investigations…high
- Winona County, Minnesota Pays $128,539.57 Ransom After January 2026 Ransomware Attack With Data Thefthigh
- PaperCut NG/MF Chained Zero-Day RCE (CVE-2026-82078 & CVE-2026-81578) Under Active Exploitationcritical
- CISA Red Team Fully Compromises Two Critical Infrastructure Orgs via ADCS ESC1 and AzureHound Cloud…high
- UNC3753 (Luna Moth / Silent Ransom Group) Vishing and Physical Intrusion Campaign Against US Law Firmshigh
- FamousSparrow APT Targets Azerbaijani Oil & Gas Sector via ProxyShell/ProxyNotShell Exchange Exploitationcritical
- Ransomware Attack Vectors: Cyble Maps Five Endpoint Blind Spots Behind the 2025-2026 Ransomware Surgemedium
- Troutman Pepper Locke LLP Data Theft Extortion by SilentRansomGroup (Repeat Attack Including Physical…high
- CVE-2026-19490 — Critical Authentication Bypass in Citrix NetScaler ADC and Gateway (CVSS 9.3) with…critical
- Insider Threat Landscape: Dark Web Recruitment & Access Broker Trends — July 2026medium
- Chaos Ransomware Group Claims 235GB PHI/Internal Document Leak from Healthcare Highways (Unconfirmed)high
- Akira Ransomware Affiliate Forces Windows Safe Mode Reboot to Disable EDR, Exfiltrates Data via…high
- Akira Ransomware Reboots Victims into Safe Mode to Blind EDR and Windows Defenderhigh
- Unit 42: Identity Compromise Is the Primary Attack Vector in Nearly 90% of Incidentshigh
- Larva-24009 (aka HeptaX) Spear-Phishing Campaign Deploys QuasarRAT, UltraVNC and Updated Notifier Backdoorhigh
- CVE-2026-50641: Plaintext Password Storage in Streamsoft Business Intelligencehigh
- DeadLock Ransomware Double-Extortion Attack on Diater (Spanish Biopharmaceutical Firm) Exposes Decade of…high
- STAC4749 Campaign: Microsoft Teams Vishing Leads to Chaos Ransomware Deploymenthigh
Detection coverage
Threadlinqs maintains 205 detection rules mapped to T1021.001 (SPL 67, KQL 83, Sigma 55). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1021 Remote Services — 364 tracked threats at the technique level.