# T1021.001 Remote Desktop Protocol

> As of 2026-10-05, T1021.001 (Remote Desktop Protocol) appears in 103 tracked threats, first reported 2026-01-27 and most recently 2026-09-27, with linked actors including Qilin, Akira, Storm-1567; it most often appears alongside T1059.001 (PowerShell).

- **Tracked threats:** 103 (33 critical, 58 high, 11 medium)
- **First seen:** 2026-01-27
- **Last seen:** 2026-09-27
- **Threat actors:** 64
- **Detection rules:** 205 (counts only; Blue tier and above)

## Key facts

- **ID:** T1021.001
- **Framework:** MITRE ATT&CK
- **Tactics:** Lateral Movement
- **Matrix:** Enterprise
- **Parent:** T1021
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1021/001/

## Activity timeline

T1021.001 first appeared in tracked threats on 2026-01-27 and was most recently reported on 2026-09-27. The busiest month was 2026-07 with 34 reports, and 103 of the 103 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1021.001 Remote Desktop Protocol is catalogued by MITRE ATT&CK under the Lateral Movement tactic in the Enterprise matrix, as a sub-technique of [T1021 Remote Services](https://intel.threadlinqs.com/technique/T1021). Threadlinqs maps 103 of 2623 tracked threats (3.9%) to it; by severity that is 33 critical, 58 high, 11 medium.

Threats that use T1021.001 most often also use [T1059.001 PowerShell](https://intel.threadlinqs.com/technique/T1059.001) (55 threats), [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (55 threats), [T1133 External Remote Services](https://intel.threadlinqs.com/technique/T1133) (53 threats), [T1685 Disable or Modify Tools](https://intel.threadlinqs.com/technique/T1685) (53 threats), [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (52 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

64 tracked threat actors appear in the threats that use T1021.001; the most frequent are [Qilin](https://intel.threadlinqs.com/actor/Qilin) (6), [Akira](https://intel.threadlinqs.com/actor/Akira) (5), [Storm-1567](https://intel.threadlinqs.com/actor/Storm-1567) (4), [APT38](https://intel.threadlinqs.com/actor/APT38) (3), [GhostEmperor](https://intel.threadlinqs.com/actor/GhostEmperor) (3).

## Mitigations

MITRE ATT&CK lists 8 mitigations for T1021.001.

- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1026 Privileged Account Management](https://attack.mitre.org/mitigations/M1026/)
- [M1028 Operating System Configuration](https://attack.mitre.org/mitigations/M1028/)
- [M1030 Network Segmentation](https://attack.mitre.org/mitigations/M1030/)
- [M1032 Multi-factor Authentication](https://attack.mitre.org/mitigations/M1032/)
- [M1035 Limit Access to Resource Over Network](https://attack.mitre.org/mitigations/M1035/)
- [M1042 Disable or Remove Feature or Program](https://attack.mitre.org/mitigations/M1042/)
- [M1047 Audit](https://attack.mitre.org/mitigations/M1047/)

## Data sources

Telemetry that can reveal T1021.001, per MITRE ATT&CK.

- Logon Session — Logon Session Creation, Logon Session Metadata
- Network Traffic — Network Connection Creation, Network Traffic Flow
- Process — Process Creation

## Threat actors using it

- [Qilin](https://intel.threadlinqs.com/actor/Qilin) — 6
- [Akira](https://intel.threadlinqs.com/actor/Akira) — 5
- [Storm-1567](https://intel.threadlinqs.com/actor/Storm-1567) — 4
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 3
- [GhostEmperor](https://intel.threadlinqs.com/actor/GhostEmperor) — 3
- [PayoutsKing](https://intel.threadlinqs.com/actor/PayoutsKing) — 3
- [Safepay](https://intel.threadlinqs.com/actor/Safepay) — 3
- [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) — 3
- [ALPHV](https://intel.threadlinqs.com/actor/ALPHV) — 2
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 2
- [Anubis](https://intel.threadlinqs.com/actor/Anubis) — 2
- [BlackCat](https://intel.threadlinqs.com/actor/BlackCat) — 2

## Tracked threats

The 30 most recent of 103 tracked threats that use T1021.001.

- [Microsoft Tracks Storm-2570 Ransomware Affiliate Behind Qilin, DragonForce, Anubis, and BERT Deployments](https://intel.threadlinqs.com/threat/TL-2026-2729) — high — 2026-09-27
- [Ryuk Ransomware Initial Access Operator Karen Vardanyan ("Maneeken") Sentenced to 24 Months in U.S. Federal…](https://intel.threadlinqs.com/threat/TL-2026-2634) — medium — 2026-09-23
- [NightEagle (APT-Q-95) Deploys GhostContainer Backdoor on Exchange, Exploits BlueKeep (CVE-2019-0708) and…](https://intel.threadlinqs.com/threat/TL-2026-2606) — critical — 2026-09-21
- [Ransomware Incidents Surge 4.7% in Japan H1 2026: The Gentlemen and Qilin Lead, AI-Assisted Tooling Observed](https://intel.threadlinqs.com/threat/TL-2026-2546) — high — 2026-09-17
- [Team Cymru Infrastructure Analysis: Seven Active Ransomware Gangs (Akira, DragonForce, Clop, MedusaLocker…](https://intel.threadlinqs.com/threat/TL-2026-2517) — high — 2026-09-15
- [Adobe Campaign Classic Critical OS Command Injection (CVE-2026-82004, APSB26-142, CVSS 10.0)](https://intel.threadlinqs.com/threat/TL-2026-2408) — critical — 2026-09-08
- [Microsoft September 2026 Patch Tuesday — 999 CVEs, 3 actively exploited zero-days (CVE-2026-85880…](https://intel.threadlinqs.com/threat/TL-2026-2407) — critical — 2026-09-08
- [Rhysida Ransomware Campaign Targeting German Public Administration (Stuttgart and Berlin, 2026)](https://intel.threadlinqs.com/threat/TL-2026-2357) — critical — 2026-09-06
- [DaVita Settles $15M Class Action Over Interlock Ransomware Breach Affecting 2.7M Patients](https://intel.threadlinqs.com/threat/TL-2026-2328) — high — 2026-09-04
- [The Gentlemen RaaS (GOLD SHERWOOD / hastalamuerte): FortiGate/VPN Intrusion Chain, GentleKiller BYOVD EDR…](https://intel.threadlinqs.com/threat/TL-2026-2271) — critical — 2026-09-01
- [BREEZE COMET (ex-UNC5669) Targets Brazilian Financial Infrastructure with AI-Assisted Custom Malware Suite](https://intel.threadlinqs.com/threat/TL-2026-2266) — critical — 2026-09-01
- [Rhysida Ransomware Claims Berlin State Government Breach Ahead of September Election](https://intel.threadlinqs.com/threat/TL-2026-2206) — high — 2026-08-29
- [Qilin Ransomware Gang Claims Breach of US ATF; Agency Confirms 'Major Incident' on Isolated Investigations…](https://intel.threadlinqs.com/threat/TL-2026-2201) — high — 2026-08-29
- [Winona County, Minnesota Pays $128,539.57 Ransom After January 2026 Ransomware Attack With Data Theft](https://intel.threadlinqs.com/threat/TL-2026-2229) — high — 2026-08-28
- [PaperCut NG/MF Chained Zero-Day RCE (CVE-2026-82078 & CVE-2026-81578) Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2184) — critical — 2026-08-28
- [CISA Red Team Fully Compromises Two Critical Infrastructure Orgs via ADCS ESC1 and AzureHound Cloud…](https://intel.threadlinqs.com/threat/TL-2026-2161) — high — 2026-08-26
- [UNC3753 (Luna Moth / Silent Ransom Group) Vishing and Physical Intrusion Campaign Against US Law Firms](https://intel.threadlinqs.com/threat/TL-2026-2127) — high — 2026-08-24
- [FamousSparrow APT Targets Azerbaijani Oil & Gas Sector via ProxyShell/ProxyNotShell Exchange Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2122) — critical — 2026-08-23
- [Ransomware Attack Vectors: Cyble Maps Five Endpoint Blind Spots Behind the 2025-2026 Ransomware Surge](https://intel.threadlinqs.com/threat/TL-2026-2110) — medium — 2026-08-22
- [Troutman Pepper Locke LLP Data Theft Extortion by SilentRansomGroup (Repeat Attack Including Physical…](https://intel.threadlinqs.com/threat/TL-2026-2103) — high — 2026-08-21
- [CVE-2026-19490 — Critical Authentication Bypass in Citrix NetScaler ADC and Gateway (CVSS 9.3) with…](https://intel.threadlinqs.com/threat/TL-2026-2080) — critical — 2026-08-20
- [Insider Threat Landscape: Dark Web Recruitment & Access Broker Trends — July 2026](https://intel.threadlinqs.com/threat/TL-2026-2078) — medium — 2026-08-20
- [Chaos Ransomware Group Claims 235GB PHI/Internal Document Leak from Healthcare Highways (Unconfirmed)](https://intel.threadlinqs.com/threat/TL-2026-2045) — high — 2026-08-17
- [Akira Ransomware Affiliate Forces Windows Safe Mode Reboot to Disable EDR, Exfiltrates Data via…](https://intel.threadlinqs.com/threat/TL-2026-2010) — high — 2026-08-13
- [Akira Ransomware Reboots Victims into Safe Mode to Blind EDR and Windows Defender](https://intel.threadlinqs.com/threat/TL-2026-2062) — high — 2026-08-12
- [Unit 42: Identity Compromise Is the Primary Attack Vector in Nearly 90% of Incidents](https://intel.threadlinqs.com/threat/TL-2026-1938) — high — 2026-08-08
- [Larva-24009 (aka HeptaX) Spear-Phishing Campaign Deploys QuasarRAT, UltraVNC and Updated Notifier Backdoor](https://intel.threadlinqs.com/threat/TL-2026-1833) — high — 2026-08-03
- [CVE-2026-50641: Plaintext Password Storage in Streamsoft Business Intelligence](https://intel.threadlinqs.com/threat/TL-2026-1825) — high — 2026-08-03
- [DeadLock Ransomware Double-Extortion Attack on Diater (Spanish Biopharmaceutical Firm) Exposes Decade of…](https://intel.threadlinqs.com/threat/TL-2026-1809) — high — 2026-08-01
- [STAC4749 Campaign: Microsoft Teams Vishing Leads to Chaos Ransomware Deployment](https://intel.threadlinqs.com/threat/TL-2026-1776) — high — 2026-07-30

## Related CVEs

CVEs referenced by the tracked threats that use T1021.001, most frequent first.

- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2020-1472](https://intel.threadlinqs.com/cve/CVE-2020-1472)
- [CVE-2021-31207](https://intel.threadlinqs.com/cve/CVE-2021-31207)
- [CVE-2021-34473](https://intel.threadlinqs.com/cve/CVE-2021-34473)
- [CVE-2021-34523](https://intel.threadlinqs.com/cve/CVE-2021-34523)
- [CVE-2022-41040](https://intel.threadlinqs.com/cve/CVE-2022-41040)
- [CVE-2022-41082](https://intel.threadlinqs.com/cve/CVE-2022-41082)
- [CVE-2023-27532](https://intel.threadlinqs.com/cve/CVE-2023-27532)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)
- [CVE-2024-37085](https://intel.threadlinqs.com/cve/CVE-2024-37085)
- [CVE-2024-40766](https://intel.threadlinqs.com/cve/CVE-2024-40766)
- [CVE-2025-26125](https://intel.threadlinqs.com/cve/CVE-2025-26125)
- [CVE-2025-32433](https://intel.threadlinqs.com/cve/CVE-2025-32433)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2025-5777](https://intel.threadlinqs.com/cve/CVE-2025-5777)
- [CVE-2026-24858](https://intel.threadlinqs.com/cve/CVE-2026-24858)
- [CVE-2017-16237](https://intel.threadlinqs.com/cve/CVE-2017-16237)
- [CVE-2018-0802](https://intel.threadlinqs.com/cve/CVE-2018-0802)
- [CVE-2019-0708](https://intel.threadlinqs.com/cve/CVE-2019-0708)
- [CVE-2019-11580](https://intel.threadlinqs.com/cve/CVE-2019-11580)
- [CVE-2020-0688](https://intel.threadlinqs.com/cve/CVE-2020-0688)
- [CVE-2021-22681](https://intel.threadlinqs.com/cve/CVE-2021-22681)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2021-26857](https://intel.threadlinqs.com/cve/CVE-2021-26857)
- [CVE-2021-26858](https://intel.threadlinqs.com/cve/CVE-2021-26858)
- [CVE-2021-27065](https://intel.threadlinqs.com/cve/CVE-2021-27065)
- [CVE-2021-27876](https://intel.threadlinqs.com/cve/CVE-2021-27876)
- [CVE-2021-27877](https://intel.threadlinqs.com/cve/CVE-2021-27877)
- [CVE-2021-27878](https://intel.threadlinqs.com/cve/CVE-2021-27878)

## Detection coverage

Threadlinqs maintains 205 detection rules mapped to T1021.001 (SPL 67, KQL 83, Sigma 55). Rule content is available to Blue tier accounts and above; this page shows counts only.

205 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1021 Remote Services](https://intel.threadlinqs.com/technique/T1021) — 364 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1021.001
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
