Exploitation of Remote Services
Description
Adversaries may exploit a software vulnerability to take advantage of a programming error in a program, service, or within the operating system software or kernel itself to enable remote service abuse. A common goal for post-compromise exploitation of remote services is for initial access into and lateral movement throughout the ICS environment to enable access to targeted systems. (Citation: Enterprise ATT&CK) ICS asset owners and operators have been affected by ransomware (or disruptive malware masquerading as ransomware) migrating from enterprise IT to ICS environments: WannaCry, NotPetya, and BadRabbit. In each of these cases, self-propagating (wormable) malware initially infected IT networks, but through exploit (particularly the SMBv1-targeting MS17-010 vulnerability) spread to industrial networks, producing significant impacts. (Citation: Joe Slowik April 2019)
Mapped SPARTA techniques
2 techniques
T0866 'Exploitation of Remote Services' is in MITRE ICS lateral-movement tactic and addresses exploiting vulnerabilities in remote services to move laterally; SPARTA LM-0001 'Hosted Payload' covers payload-to-bus pivot which exploits the payload-bus interface as the remote service granting cross-partition movement. Tactic and activity align directly.
Exploiting lack of bus segregation lets the adversary traverse subsystems via unsegregated bus paths — exact instance of T0866 'Exploitation of Remote Services' applied to inter-subsystem bus interfaces. Tactic and activity align (lateral-movement).
Cite as SafeMode Space, mitre-attack-ics T0866.