Activity timeline
T1021.005 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 4 reports, and 11 of the 11 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1021.005 VNC is catalogued by MITRE ATT&CK under the Lateral Movement tactic in the Enterprise matrix, as a sub-technique of T1021 Remote Services. Threadlinqs maps 11 of 2623 tracked threats (0.4%) to it; by severity that is 3 critical, 5 high, 3 medium.
Threats that use T1021.005 most often also use T1133 External Remote Services (6 threats), T1204.002 Malicious File (6 threats), T1005 Data from Local System (5 threats), T1057 Process Discovery (5 threats), T1082 System Information Discovery (5 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
9 tracked threat actors appear in the threats that use T1021.005; the most frequent are NoName057(16) (2), APT44 (1), Cavern Manticore (1), Dark Caracal (1), Gamaredon Group (1).
Mitigations
MITRE ATT&CK lists 4 mitigations for T1021.005.
Data sources
Telemetry that can reveal T1021.005, per MITRE ATT&CK.
- Logon Session — Logon Session Creation
- Network Traffic — Network Connection Creation
- Process — Process Creation
Threat actors using it
Tracked threats
11 tracked threats use T1021.005.
- France Dark Web Threat Landscape: Ransomware and Hacktivist Activity Surges 4x Over 24 Monthshigh
- Dark Caracal Deploys New GoCaracal Malware with Ethereum-Based C2 Resilience in Venezuela Breachhigh
- SynkLoader: Modular Multi-Language Loader Deployed via Microsoft Teams Phishing, Likely Ransomware Precursorhigh
- CVE-2026-43760: macOS Screen Sharing Logic Flaw Allows VNC-Authenticated Root Command Executioncritical
- CVE-2026-65400: macOS Screen Sharing Authentication Bypass Grants Unauthenticated Root Accesscritical
- HOLLOWGRAPH: .NET NativeAOT Malware Abusing Microsoft Graph API and M365 Calendar Events for C2, Linked to…high
- Latrodectus Loader: Three-Stage JScript/VBScript Obfuscation Delivers WMI/msiexec MSI Payload…medium
- Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domainsmedium
- GigaWiper (BLUERABBIT): Golang Backdoor Bundling Physical-Disk Wiping, Crucio-Derived Fake Ransomware, and…high
- The Remote Access Blind Spot: Acronis TRU Analysis of RMM Tool Proliferation and Abuse Risk in SMB…medium
- Pro-Russia Hacktivists (CARR/Z-Pentest/NoName057/Sector16) — GRU Unit 74455-Linked OT/ICS Attacks on US and…critical
Detection coverage
Threadlinqs maintains 31 detection rules mapped to T1021.005 (SPL 10, KQL 11, Sigma 10). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1021 Remote Services — 364 tracked threats at the technique level.