# T1021.005 VNC

> As of 2026-10-05, T1021.005 (VNC) appears in 11 tracked threats, first reported 2026-02-21 and most recently 2026-09-18, with linked actors including NoName057(16), APT44, Cavern Manticore; it most often appears alongside T1133 (External Remote Services).

- **Tracked threats:** 11 (3 critical, 5 high, 3 medium)
- **First seen:** 2026-02-21
- **Last seen:** 2026-09-18
- **Threat actors:** 9
- **Detection rules:** 31 (counts only; Blue tier and above)

## Key facts

- **ID:** T1021.005
- **Framework:** MITRE ATT&CK
- **Tactics:** Lateral Movement
- **Matrix:** Enterprise
- **Parent:** T1021
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1021/005/

## Activity timeline

T1021.005 first appeared in tracked threats on 2026-02-21 and was most recently reported on 2026-09-18. The busiest month was 2026-07 with 4 reports, and 11 of the 11 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1021.005 VNC is catalogued by MITRE ATT&CK under the Lateral Movement tactic in the Enterprise matrix, as a sub-technique of [T1021 Remote Services](https://intel.threadlinqs.com/technique/T1021). Threadlinqs maps 11 of 2623 tracked threats (0.4%) to it; by severity that is 3 critical, 5 high, 3 medium.

Threats that use T1021.005 most often also use [T1133 External Remote Services](https://intel.threadlinqs.com/technique/T1133) (6 threats), [T1204.002 Malicious File](https://intel.threadlinqs.com/technique/T1204.002) (6 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (5 threats), [T1057 Process Discovery](https://intel.threadlinqs.com/technique/T1057) (5 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (5 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

9 tracked threat actors appear in the threats that use T1021.005; the most frequent are [NoName057(16)](https://intel.threadlinqs.com/actor/NoName057(16)) (2), [APT44](https://intel.threadlinqs.com/actor/APT44) (1), [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) (1), [Dark Caracal](https://intel.threadlinqs.com/actor/Dark%20Caracal) (1), [Gamaredon Group](https://intel.threadlinqs.com/actor/Gamaredon%20Group) (1).

## Mitigations

MITRE ATT&CK lists 4 mitigations for T1021.005.

- [M1033 Limit Software Installation](https://attack.mitre.org/mitigations/M1033/)
- [M1037 Filter Network Traffic](https://attack.mitre.org/mitigations/M1037/)
- [M1042 Disable or Remove Feature or Program](https://attack.mitre.org/mitigations/M1042/)
- [M1047 Audit](https://attack.mitre.org/mitigations/M1047/)

## Data sources

Telemetry that can reveal T1021.005, per MITRE ATT&CK.

- Logon Session — Logon Session Creation
- Network Traffic — Network Connection Creation
- Process — Process Creation

## Threat actors using it

- [NoName057(16)](https://intel.threadlinqs.com/actor/NoName057(16)) — 2
- [APT44](https://intel.threadlinqs.com/actor/APT44) — 1
- [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) — 1
- [Dark Caracal](https://intel.threadlinqs.com/actor/Dark%20Caracal) — 1
- [Gamaredon Group](https://intel.threadlinqs.com/actor/Gamaredon%20Group) — 1
- [MedusaLocker](https://intel.threadlinqs.com/actor/MedusaLocker) — 1
- [Qilin](https://intel.threadlinqs.com/actor/Qilin) — 1
- [Sandworm](https://intel.threadlinqs.com/actor/Sandworm) — 1
- [TA578 - G1038](https://intel.threadlinqs.com/actor/TA578%20-%20G1038) — 1

## Tracked threats

11 tracked threats use T1021.005.

- [France Dark Web Threat Landscape: Ransomware and Hacktivist Activity Surges 4x Over 24 Months](https://intel.threadlinqs.com/threat/TL-2026-2564) — high — 2026-09-18
- [Dark Caracal Deploys New GoCaracal Malware with Ethereum-Based C2 Resilience in Venezuela Breach](https://intel.threadlinqs.com/threat/TL-2026-2219) — high — 2026-08-29
- [SynkLoader: Modular Multi-Language Loader Deployed via Microsoft Teams Phishing, Likely Ransomware Precursor](https://intel.threadlinqs.com/threat/TL-2026-2131) — high — 2026-08-24
- [CVE-2026-43760: macOS Screen Sharing Logic Flaw Allows VNC-Authenticated Root Command Execution](https://intel.threadlinqs.com/threat/TL-2026-2038) — critical — 2026-08-16
- [CVE-2026-65400: macOS Screen Sharing Authentication Bypass Grants Unauthenticated Root Access](https://intel.threadlinqs.com/threat/TL-2026-1925) — critical — 2026-08-07
- [HOLLOWGRAPH: .NET NativeAOT Malware Abusing Microsoft Graph API and M365 Calendar Events for C2, Linked to…](https://intel.threadlinqs.com/threat/TL-2026-1553) — high — 2026-07-20
- [Latrodectus Loader: Three-Stage JScript/VBScript Obfuscation Delivers WMI/msiexec MSI Payload…](https://intel.threadlinqs.com/threat/TL-2026-1486) — medium — 2026-07-18
- [Passive DNS Pivoting Uncovers 122 New ACTINIUM (Gamaredon) Infrastructure Domains](https://intel.threadlinqs.com/threat/TL-2026-1484) — medium — 2026-07-18
- [GigaWiper (BLUERABBIT): Golang Backdoor Bundling Physical-Disk Wiping, Crucio-Derived Fake Ransomware, and…](https://intel.threadlinqs.com/threat/TL-2026-1271) — high — 2026-07-13
- [The Remote Access Blind Spot: Acronis TRU Analysis of RMM Tool Proliferation and Abuse Risk in SMB…](https://intel.threadlinqs.com/threat/TL-2026-2115) — medium — 2026-05-13
- [Pro-Russia Hacktivists (CARR/Z-Pentest/NoName057/Sector16) — GRU Unit 74455-Linked OT/ICS Attacks on US and…](https://intel.threadlinqs.com/threat/TL-2026-0125) — critical — 2026-02-21

## Related CVEs

CVEs referenced by the tracked threats that use T1021.005, most frequent first.

- [CVE-2026-43760](https://intel.threadlinqs.com/cve/CVE-2026-43760)
- [CVE-2024-1708](https://intel.threadlinqs.com/cve/CVE-2024-1708)
- [CVE-2024-1709](https://intel.threadlinqs.com/cve/CVE-2024-1709)
- [CVE-2026-65400](https://intel.threadlinqs.com/cve/CVE-2026-65400)

## Detection coverage

Threadlinqs maintains 31 detection rules mapped to T1021.005 (SPL 10, KQL 11, Sigma 10). Rule content is available to Blue tier accounts and above; this page shows counts only.

31 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1021 Remote Services](https://intel.threadlinqs.com/technique/T1021) — 364 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1021.005
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
