# T1021.006 Windows Remote Management

> As of 2026-10-05, T1021.006 (Windows Remote Management) appears in 12 tracked threats, first reported 2026-02-06 and most recently 2026-09-23, with linked actors including Cavern Manticore, ALPHV, APT34; it most often appears alongside T1071.001 (Web Protocols).

- **Tracked threats:** 12 (4 critical, 7 high, 1 medium)
- **First seen:** 2026-02-06
- **Last seen:** 2026-09-23
- **Threat actors:** 7
- **Detection rules:** 26 (counts only; Blue tier and above)

## Key facts

- **ID:** T1021.006
- **Framework:** MITRE ATT&CK
- **Tactics:** Lateral Movement
- **Matrix:** Enterprise
- **Parent:** T1021
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1021/006/

## Activity timeline

T1021.006 first appeared in tracked threats on 2026-02-06 and was most recently reported on 2026-09-23. The busiest month was 2026-07 with 6 reports, and 12 of the 12 threats were reported in the twelve months to 2026-09.

## How adversaries use it

T1021.006 Windows Remote Management is catalogued by MITRE ATT&CK under the Lateral Movement tactic in the Enterprise matrix, as a sub-technique of [T1021 Remote Services](https://intel.threadlinqs.com/technique/T1021). Threadlinqs maps 12 of 2623 tracked threats (0.5%) to it; by severity that is 4 critical, 7 high, 1 medium.

Threats that use T1021.006 most often also use [T1071.001 Web Protocols](https://intel.threadlinqs.com/technique/T1071.001) (7 threats), [T1078 Valid Accounts](https://intel.threadlinqs.com/technique/T1078) (7 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (6 threats), [T1018 Remote System Discovery](https://intel.threadlinqs.com/technique/T1018) (6 threats), [T1490 Inhibit System Recovery](https://intel.threadlinqs.com/technique/T1490) (6 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

7 tracked threat actors appear in the threats that use T1021.006; the most frequent are [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) (2), [ALPHV](https://intel.threadlinqs.com/actor/ALPHV) (1), [APT34](https://intel.threadlinqs.com/actor/APT34) (1), [Qilin ransomware affiliate](https://intel.threadlinqs.com/actor/Qilin%20ransomware%20affiliate) (1), [STORM-0501](https://intel.threadlinqs.com/actor/STORM-0501) (1).

## Mitigations

MITRE ATT&CK lists 3 mitigations for T1021.006.

- [M1026 Privileged Account Management](https://attack.mitre.org/mitigations/M1026/)
- [M1030 Network Segmentation](https://attack.mitre.org/mitigations/M1030/)
- [M1042 Disable or Remove Feature or Program](https://attack.mitre.org/mitigations/M1042/)

## Data sources

Telemetry that can reveal T1021.006, per MITRE ATT&CK.

- Command — Command Execution
- Logon Session — Logon Session Creation
- Network Traffic — Network Connection Creation, Network Traffic Flow
- Process — Process Creation
- Service — Service Metadata

## Threat actors using it

- [Cavern Manticore](https://intel.threadlinqs.com/actor/Cavern%20Manticore) — 2
- [ALPHV](https://intel.threadlinqs.com/actor/ALPHV) — 1
- [APT34](https://intel.threadlinqs.com/actor/APT34) — 1
- [Qilin ransomware affiliate](https://intel.threadlinqs.com/actor/Qilin%20ransomware%20affiliate) — 1
- [STORM-0501](https://intel.threadlinqs.com/actor/STORM-0501) — 1
- [Storm-2603](https://intel.threadlinqs.com/actor/Storm-2603) — 1
- [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) — 1

## Tracked threats

12 tracked threats use T1021.006.

- [Eclypsium InfraTrust Report: Mass Active Exploitation of Network Management Systems (Cisco FMC/ISE…](https://intel.threadlinqs.com/threat/TL-2026-2630) — critical — 2026-09-23
- [Impersonating IT Support: Threat Actors Turn Remote Sessions into Enterprise-Wide Access via Microsoft Teams](https://intel.threadlinqs.com/threat/TL-2026-2302) — high — 2026-09-02
- [Aurora Ransomware Affiliate Uses Cursor AI Coding Assistant for Attack Planning, ADCS Abuse Across 20+ Victims](https://intel.threadlinqs.com/threat/TL-2026-2165) — high — 2026-08-27
- [CVE-2026-20316: Cisco Secure Firewall Management Center Hard-coded Password Vulnerability Added to CISA KEV](https://intel.threadlinqs.com/threat/TL-2026-1759) — critical — 2026-07-29
- [Project CAV3RN / Cavern Manticore: Iran-Linked Modular Cyberespionage Framework Abuses Outlook Calendar…](https://intel.threadlinqs.com/threat/TL-2026-1588) — high — 2026-07-21
- [HOLLOWGRAPH: .NET NativeAOT Malware Abusing Microsoft Graph API and M365 Calendar Events for C2, Linked to…](https://intel.threadlinqs.com/threat/TL-2026-1553) — high — 2026-07-20
- [Spirals Ransomware Targets South Asian IT Services Firm via IIS Web Shell, Chisel Tunneling, and Sub-24-Hour…](https://intel.threadlinqs.com/threat/TL-2026-1448) — high — 2026-07-17
- [July 2026 Patch Tuesday: Actively Exploited SharePoint RCE (CVE-2026-58644) and AD FS/SharePoint Zero-Days](https://intel.threadlinqs.com/threat/TL-2026-1437) — critical — 2026-07-17
- [npm 12 Disables Install Scripts, Git Dependencies, and Remote Tarball URLs by Default to Curb Supply-Chain…](https://intel.threadlinqs.com/threat/TL-2026-1163) — medium — 2026-07-10
- [Four Methods for Azure Blob Storage Ransomware: Client-Side Bulk Encryption, CPK, Encryption Scope, and CMK…](https://intel.threadlinqs.com/threat/TL-2026-2191) — high — 2026-06-15
- [The Gentlemen Ransomware (RaaS) — Defense Evasion TTPs: Event Log Clearing, Defender Disable & AV Exclusions…](https://intel.threadlinqs.com/threat/TL-2026-0555) — high — 2026-05-21
- [Nitrogen Ransomware Coding Bug Permanently Destroys ESXi Data — Curve25519 Memory Corruption Makes…](https://intel.threadlinqs.com/threat/TL-2026-0105) — critical — 2026-02-06

## Related CVEs

CVEs referenced by the tracked threats that use T1021.006, most frequent first.

- [CVE-2026-20079](https://intel.threadlinqs.com/cve/CVE-2026-20079)
- [CVE-2026-20316](https://intel.threadlinqs.com/cve/CVE-2026-20316)
- [CVE-2017-0144](https://intel.threadlinqs.com/cve/CVE-2017-0144)
- [CVE-2026-20131](https://intel.threadlinqs.com/cve/CVE-2026-20131)
- [CVE-2026-31431](https://intel.threadlinqs.com/cve/CVE-2026-31431)
- [CVE-2026-32201](https://intel.threadlinqs.com/cve/CVE-2026-32201)
- [CVE-2026-45659](https://intel.threadlinqs.com/cve/CVE-2026-45659)
- [CVE-2026-50522](https://intel.threadlinqs.com/cve/CVE-2026-50522)
- [CVE-2026-50661](https://intel.threadlinqs.com/cve/CVE-2026-50661)
- [CVE-2026-55040](https://intel.threadlinqs.com/cve/CVE-2026-55040)
- [CVE-2026-56155](https://intel.threadlinqs.com/cve/CVE-2026-56155)
- [CVE-2026-56164](https://intel.threadlinqs.com/cve/CVE-2026-56164)
- [CVE-2026-57092](https://intel.threadlinqs.com/cve/CVE-2026-57092)
- [CVE-2026-58644](https://intel.threadlinqs.com/cve/CVE-2026-58644)
- [CVE-2026-76460](https://intel.threadlinqs.com/cve/CVE-2026-76460)
- [CVE-2026-83548](https://intel.threadlinqs.com/cve/CVE-2026-83548)
- [CVE-2026-83549](https://intel.threadlinqs.com/cve/CVE-2026-83549)
- [CVE-2026-85102](https://intel.threadlinqs.com/cve/CVE-2026-85102)
- [CVE-2026-85103](https://intel.threadlinqs.com/cve/CVE-2026-85103)
- [CVE-2026-91843](https://intel.threadlinqs.com/cve/CVE-2026-91843)

## Detection coverage

Threadlinqs maintains 26 detection rules mapped to T1021.006 (SPL 7, KQL 12, Sigma 7). Rule content is available to Blue tier accounts and above; this page shows counts only.

26 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1021 Remote Services](https://intel.threadlinqs.com/technique/T1021) — 364 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1021.006
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
