Skip to content

T1021.005 VNC

Adversaries may use Valid Accounts to remotely control machines using Virtual Network Computing (VNC). VNC is a platform-independent desktop sharing system that uses the RFB (“remote framebuffer”) protocol to enable users to remotely control another computer’s display by relaying the screen, mouse, and keyboard inputs over the network.10

VNC differs from Remote Desktop Protocol as VNC is screen-sharing software rather than resource-sharing software. By default, VNC uses the system’s authentication, but it can be configured to use credentials specific to VNC.211

Adversaries may abuse VNC to perform malicious actions as the logged-on user such as opening documents, downloading files, and running arbitrary commands. An adversary could use VNC to remotely control and monitor a system to collect data and information to pivot to other systems within the network. Specific VNC libraries/implementations have also been susceptible to brute force attacks and memory usage exploitation.1249513

Item Value
ID T1021.005
Sub-techniques T1021.001, T1021.002, T1021.003, T1021.004, T1021.005, T1021.006, T1021.007, T1021.008
Tactics TA0008
Platforms Linux, Windows, macOS
Version 1.2
Created 11 February 2020
Last Modified 24 October 2025

Procedure Examples

ID Name Description
S0484 Carberp Carberp can start a remote VNC session by downloading a new plugin.15
S1014 DanBot DanBot can use VNC for remote access to targeted systems.14
G0046 FIN7 FIN7 has used TightVNC to control compromised hosts.24
G0117 Fox Kitten Fox Kitten has installed TightVNC server and client on compromised servers and endpoints for lateral movement.26
G0047 Gamaredon Group Gamaredon Group has used VNC tools, including UltraVNC, to remotely interact with compromised hosts.222123
G0036 GCMAN GCMAN uses VNC for lateral movement.25
S1160 Latrodectus
Latrodectus has routed C2 traffic using Keyhole VNC.20
S0279 Proton Proton uses VNC to connect into systems.18
S0266 TrickBot TrickBot has used a VNC module to monitor the victim and collect information to pivot to valuable systems on the network 1617
S0670 WarzoneRAT WarzoneRAT has the ability of performing remote desktop access via a VNC console.19
S0412 ZxShell ZxShell supports functionality for VNC sessions.13

Mitigations

ID Mitigation Description
M1047 Audit Inventory workstations for unauthorized VNC server software.
M1042 Disable or Remove Feature or Program Uninstall any VNC server software where not required.
M1037 Filter Network Traffic VNC defaults to TCP ports 5900 for the server, 5800 for browser access, and 5500 for a viewer in listening mode. Filtering or blocking these ports will inhibit VNC traffic utilizing default ports.
M1033 Limit Software Installation Restrict software installation to user groups that require it. A VNC server must be manually installed by the user or adversary.

References


  1. Administrator, Penetration Testing Lab. (2012, October 30). Attacking VNC Servers. Retrieved October 6, 2021. ↩

  2. Apple Support. (n.d.). Set up a computer running VNC software for Remote Desktop. Retrieved August 18, 2021. ↩

  3. Jay Pipes. (2013, December 23). Security Breach! Tenant A is seeing the VNC Consoles of Tenant B!. Retrieved September 12, 2024. ↩

  4. Nick Miles. (2017, November 30). Detecting macOS High Sierra root account without authentication. Retrieved September 20, 2021. ↩

  5. Offensive Security. (n.d.). VNC Authentication. Retrieved October 6, 2021. ↩

  6. Pascal Nowack. (n.d.). Retrieved September 21, 2021. ↩

  7. Pascal Nowack. (n.d.). Retrieved September 21, 2021. ↩

  8. Sarah Edwards. (2020, April 30). Analysis of Apple Unified Logs: Quarantine Edition [Entry 6] – Working From Home? Remote Logins. Retrieved August 19, 2021. ↩

  9. Sergiu Gatlan. (2019, November 22). Dozens of VNC Vulnerabilities Found in Linux, Windows Solutions. Retrieved September 20, 2021. ↩

  10. T. Richardson, J. Levine, RealVNC Ltd.. (2011, March). The Remote Framebuffer Protocol. Retrieved September 20, 2021. ↩

  11. Tegan. (2019, August 15). Setting up System Authentication. Retrieved September 20, 2021. ↩

  12. Z3RO. (2019, March 10). Day 70: Hijacking VNC (Enum, Brute, Access and Crack). Retrieved September 20, 2021. ↩

  13. Allievi, A., et al. (2014, October 28). Threat Spotlight: Group 72, Opening the ZxShell. Retrieved September 24, 2019. ↩

  14. ClearSky Cyber Security . (2021, August). New Iranian Espionage Campaign By “Siamesekitten” - Lyceum. Retrieved June 6, 2022. ↩

  15. Giuliani, M., Allievi, A. (2011, February 28). Carberp - a modular information stealing trojan. Retrieved September 12, 2024. ↩

  16. Ionut Illascu. (2021, July 14). Trickbot updates its VNC module for high-value targets. Retrieved September 10, 2021. ↩

  17. Radu Tudorica. (2021, July 12). A Fresh Look at Trickbot’s Ever-Improving VNC Module. Retrieved September 28, 2021. ↩

  18. Patrick Wardle. (n.d.). Mac Malware of 2017. Retrieved September 21, 2018. ↩

  19. Harakhavik, Y. (2020, February 3). Warzone: Behind the enemy lines. Retrieved December 17, 2021. ↩

  20. Unit 42. (2024, June 25). 2024-06-25-IOCs-from-Latrodectus-activity. Retrieved September 13, 2024. ↩

  21. Microsoft Threat Intelligence Center. (2022, February 4). ACTINIUM targets Ukrainian organizations. Retrieved February 18, 2022. ↩

  22. Symantec. (2022, January 31). Shuckworm Continues Cyber-Espionage Attacks Against Ukraine. Retrieved February 17, 2022. ↩

  23. Unit 42. (2022, February 3). Russia’s Gamaredon aka Primitive Bear APT Group Actively Targeting Ukraine. Retrieved February 21, 2022. ↩

  24. Loui, E. and Reynolds, J. (2021, August 30). CARBON SPIDER Embraces Big Game Hunting, Part 1. Retrieved September 20, 2021. ↩

  25. Kaspersky Lab’s Global Research & Analysis Team. (2016, February 8). APT-style bank robberies increase with Metel, GCMAN and Carbanak 2.0 attacks. Retrieved April 20, 2016. ↩

  26. CISA. (2020, September 15). Iran-Based Threat Actor Exploits VPN Vulnerabilities. Retrieved December 21, 2020. ↩