# T1021 Remote Services

> As of 2026-10-05, T1021 (Remote Services) appears in 364 tracked threats, first reported 2026-01-19 and most recently 2026-10-02, with linked actors including MuddyWater, Static Tundra, TeamPCP; it most often appears alongside T1059 (Command and Scripting Interpreter).

- **Tracked threats:** 364 (171 critical, 160 high, 24 medium, 2 low)
- **First seen:** 2026-01-19
- **Last seen:** 2026-10-02
- **Threat actors:** 131
- **Detection rules:** 204 (counts only; Blue tier and above)

## Key facts

- **ID:** T1021
- **Framework:** MITRE ATT&CK
- **Tactics:** Lateral Movement
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1021/

## Activity timeline

T1021 first appeared in tracked threats on 2026-01-19 and was most recently reported on 2026-10-02. The busiest month was 2026-07 with 133 reports, and 364 of the 364 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1021 Remote Services is catalogued by MITRE ATT&CK under the Lateral Movement tactic in the Enterprise matrix. Threadlinqs maps 364 of 2623 tracked threats (13.9%) to it; by severity that is 171 critical, 160 high, 24 medium, 2 low.

Threats that use T1021 most often also use [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (273 threats), [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (240 threats), [T1071 Application Layer Protocol](https://intel.threadlinqs.com/technique/T1071) (222 threats), [T1078 Valid Accounts](https://intel.threadlinqs.com/technique/T1078) (216 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (189 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

131 tracked threat actors appear in the threats that use T1021; the most frequent are [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) (7), [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) (7), [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (7), [LockBit](https://intel.threadlinqs.com/actor/LockBit) (6), [Qilin](https://intel.threadlinqs.com/actor/Qilin) (6).

## Mitigations

MITRE ATT&CK lists 6 mitigations for T1021.

- [M1018 User Account Management](https://attack.mitre.org/mitigations/M1018/)
- [M1027 Password Policies](https://attack.mitre.org/mitigations/M1027/)
- [M1032 Multi-factor Authentication](https://attack.mitre.org/mitigations/M1032/)
- [M1035 Limit Access to Resource Over Network](https://attack.mitre.org/mitigations/M1035/)
- [M1042 Disable or Remove Feature or Program](https://attack.mitre.org/mitigations/M1042/)
- [M1047 Audit](https://attack.mitre.org/mitigations/M1047/)

## Data sources

Telemetry that can reveal T1021, per MITRE ATT&CK.

- Command — Command Execution
- Logon Session — Logon Session Creation
- Module — Module Load
- Network Share — Network Share Access
- Network Traffic — Network Connection Creation, Network Traffic Flow
- Process — Process Creation
- WMI — WMI Creation

## Threat actors using it

- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 7
- [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) — 7
- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 7
- [LockBit](https://intel.threadlinqs.com/actor/LockBit) — 6
- [Qilin](https://intel.threadlinqs.com/actor/Qilin) — 6
- [Sandworm](https://intel.threadlinqs.com/actor/Sandworm) — 6
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 5
- [Forest Blizzard](https://intel.threadlinqs.com/actor/Forest%20Blizzard) — 5
- [Storm-2603](https://intel.threadlinqs.com/actor/Storm-2603) — 5
- [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) — 5
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 4
- [APT44](https://intel.threadlinqs.com/actor/APT44) — 4

## Tracked threats

The 30 most recent of 364 tracked threats that use T1021.

- [CISA adds two Zammad vulnerabilities to KEV: CVE-2026-102489 (session fixation to RCE) and CVE-2026-102490…](https://intel.threadlinqs.com/threat/TL-2026-2843) — critical — 2026-10-02
- [Storm-3168 (JADEPUFFER): Agentic-Driven Destructive Cloud Attacks Against Azure via Compromised Service…](https://intel.threadlinqs.com/threat/TL-2026-2666) — critical — 2026-09-26
- [Cyberattack Disrupts Dyfed-Powys Police Systems in Wales, Staff Data Possibly Compromised](https://intel.threadlinqs.com/threat/TL-2026-2694) — medium — 2026-09-25
- [Ransomware Attack Disrupts IT Systems and Services in Ellis County, Kansas](https://intel.threadlinqs.com/threat/TL-2026-2571) — high — 2026-09-18
- [Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH Against India and…](https://intel.threadlinqs.com/threat/TL-2026-2545) — high — 2026-09-16
- [Rehub: Russian-Language Ransomware-as-a-Service Marketplace Absorbing RAMP's Displaced Operators](https://intel.threadlinqs.com/threat/TL-2026-2532) — medium — 2026-09-16
- [VSS Abuse: Attackers Weaponize Windows Volume Shadow Copy Service for Ransomware Prep and Credential Theft](https://intel.threadlinqs.com/threat/TL-2026-2505) — high — 2026-09-14
- [CVE-2025-25249: Fortinet Heap-Based Buffer Overflow Exploited to Deploy PivotC2 RAT on FortiGate Devices](https://intel.threadlinqs.com/threat/TL-2026-2431) — critical — 2026-09-10
- [CVE-2026-86218 — Unauthenticated Pre-Auth Remote Code Execution in N-able N-central (Active Exploitation…](https://intel.threadlinqs.com/threat/TL-2026-2415) — critical — 2026-09-09
- [Hyadina Rebrands Beast Ransomware as 'GodDamn' and Uses PoisonX Signed Kernel Driver to Disable Endpoint…](https://intel.threadlinqs.com/threat/TL-2026-2409) — critical — 2026-09-08
- [Microsoft September 2026 Patch Tuesday — 999 CVEs, 3 actively exploited zero-days (CVE-2026-85880…](https://intel.threadlinqs.com/threat/TL-2026-2407) — critical — 2026-09-08
- [September 2026 Microsoft Patch Tuesday — Record 966+ Vulnerabilities with Two Actively Exploited Zero-Days…](https://intel.threadlinqs.com/threat/TL-2026-2398) — critical — 2026-09-08
- [Ivanti September 2026 Patch Batch: 10 CVEs Across EPMM, Neurons for ITSM, and Sentry (CVE-2026-12744/12745…](https://intel.threadlinqs.com/threat/TL-2026-2396) — critical — 2026-09-08
- [Telerik UI for ASP.NET AJAX — Padding Oracle Chained to Unauthenticated Deserialization RCE…](https://intel.threadlinqs.com/threat/TL-2026-2369) — high — 2026-09-07
- [DragonForce Ransomware Attack on RubberMill, Inc. — ~340GB Data Exfiltration Including PII, Credentials, CAD…](https://intel.threadlinqs.com/threat/TL-2026-2364) — critical — 2026-09-06
- [Vexy Ransomware hits Mega Velocity — 46.68 GB exfiltrated, double extortion](https://intel.threadlinqs.com/threat/TL-2026-2363) — high — 2026-09-06
- [Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication (MikroTrick)](https://intel.threadlinqs.com/threat/TL-2026-2345) — critical — 2026-09-06
- [Chinese-Speaking Operator "Nie" Uses SecFlow AI Orchestration Framework (Claude, Qwen, DeepSeek) and GLUTTON…](https://intel.threadlinqs.com/threat/TL-2026-2325) — high — 2026-09-04
- [ORB Networks and Nation-State CNI Targeting: Destructive Wiper Attack on Polish Energy Infrastructure via…](https://intel.threadlinqs.com/threat/TL-2026-2317) — high — 2026-09-03
- [HPE Patches Critical ArubaOS-CX Buffer Overflow (CVE-2026-73749) Enabling Unauthenticated Remote Code…](https://intel.threadlinqs.com/threat/TL-2026-2314) — critical — 2026-09-03
- [Mustang Panda Targets India's Government and Energy Sectors with SHARDLOADER, MINIRECON, and ZOHOMURK](https://intel.threadlinqs.com/threat/TL-2026-2293) — high — 2026-09-02
- [Aur0ra Ransomware Group: Xray-core C2 Tunneling, Aggressive Email Bombing, and Log-Wiping Double-Extortion…](https://intel.threadlinqs.com/threat/TL-2026-2278) — high — 2026-09-01
- [Chaos Ransomware Claims MacAllister (macallister.com) — 75GB Data Exfiltration Claimed, Leadership Refused…](https://intel.threadlinqs.com/threat/TL-2026-2209) — high — 2026-08-28
- [PaperCut NG/MF Application Server Zero-Day: Unauthenticated RCE Under Active Exploitation, No CVE Assigned](https://intel.threadlinqs.com/threat/TL-2026-2179) — critical — 2026-08-28
- [PaperCut NG/MF Print Management Software Under Active Exploitation of Unpatched Vulnerability](https://intel.threadlinqs.com/threat/TL-2026-2171) — high — 2026-08-27
- [SLEEPWALKER: Passive-Trigger Windows Backdoor Masquerading as dpapi.dll via ERAAgent.exe Side-Loading](https://intel.threadlinqs.com/threat/TL-2026-2166) — medium — 2026-08-27
- [Dark Caracal Expands Espionage Arsenal with GoCaracal Framework and AsioGate Backdoor](https://intel.threadlinqs.com/threat/TL-2026-2158) — high — 2026-08-26
- [Edge Infrastructure Under Siege: Tenable and SentinelOne Datasets Reveal Convergent Nation-State and…](https://intel.threadlinqs.com/threat/TL-2026-2153) — high — 2026-08-26
- [JA4H Fingerprinting Detects Sliver C2 Deployed via Chained PAN-OS CVE-2024-0012/CVE-2024-9474 Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2144) — high — 2026-08-25
- [2026 Ransomware Surge Targeting US Organizations: Identity-First Compromise, BYOVD, and Living-Off-the-Cloud…](https://intel.threadlinqs.com/threat/TL-2026-2125) — high — 2026-08-23

## Related CVEs

CVEs referenced by the tracked threats that use T1021, most frequent first.

- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2026-45659](https://intel.threadlinqs.com/cve/CVE-2026-45659)
- [CVE-2026-56164](https://intel.threadlinqs.com/cve/CVE-2026-56164)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2021-44228](https://intel.threadlinqs.com/cve/CVE-2021-44228)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2024-21762](https://intel.threadlinqs.com/cve/CVE-2024-21762)
- [CVE-2024-21887](https://intel.threadlinqs.com/cve/CVE-2024-21887)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2026-15409](https://intel.threadlinqs.com/cve/CVE-2026-15409)
- [CVE-2026-32201](https://intel.threadlinqs.com/cve/CVE-2026-32201)
- [CVE-2026-56155](https://intel.threadlinqs.com/cve/CVE-2026-56155)
- [CVE-2016-4437](https://intel.threadlinqs.com/cve/CVE-2016-4437)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2023-46805](https://intel.threadlinqs.com/cve/CVE-2023-46805)
- [CVE-2023-4966](https://intel.threadlinqs.com/cve/CVE-2023-4966)
- [CVE-2024-1709](https://intel.threadlinqs.com/cve/CVE-2024-1709)
- [CVE-2024-53704](https://intel.threadlinqs.com/cve/CVE-2024-53704)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2026-15410](https://intel.threadlinqs.com/cve/CVE-2026-15410)
- [CVE-2026-50661](https://intel.threadlinqs.com/cve/CVE-2026-50661)
- [CVE-2026-58644](https://intel.threadlinqs.com/cve/CVE-2026-58644)
- [CVE-2018-13379](https://intel.threadlinqs.com/cve/CVE-2018-13379)
- [CVE-2021-22681](https://intel.threadlinqs.com/cve/CVE-2021-22681)
- [CVE-2021-27076](https://intel.threadlinqs.com/cve/CVE-2021-27076)
- [CVE-2021-36260](https://intel.threadlinqs.com/cve/CVE-2021-36260)
- [CVE-2022-27925](https://intel.threadlinqs.com/cve/CVE-2022-27925)
- [CVE-2022-41082](https://intel.threadlinqs.com/cve/CVE-2022-41082)
- [CVE-2023-20198](https://intel.threadlinqs.com/cve/CVE-2023-20198)
- [CVE-2023-27350](https://intel.threadlinqs.com/cve/CVE-2023-27350)

## Detection coverage

Threadlinqs maintains 204 detection rules mapped to T1021 (SPL 64, KQL 75, Sigma 65). Rule content is available to Blue tier accounts and above; this page shows counts only.

204 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Sub-techniques

- [T1021.001 Remote Desktop Protocol](https://intel.threadlinqs.com/technique/T1021.001) — 103 tracked threats
- [T1021.002 SMB/Windows Admin Shares](https://intel.threadlinqs.com/technique/T1021.002) — 90 tracked threats
- T1021.003 Distributed Component Object Model — 3 tracked threats
- [T1021.004 SSH](https://intel.threadlinqs.com/technique/T1021.004) — 63 tracked threats
- [T1021.005 VNC](https://intel.threadlinqs.com/technique/T1021.005) — 11 tracked threats
- [T1021.006 Windows Remote Management](https://intel.threadlinqs.com/technique/T1021.006) — 12 tracked threats
- T1021.007 Cloud Services — 6 tracked threats
- T1021.008 Direct Cloud VM Connections — 0 tracked threats

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1021
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
