MITRE ATT&CK ICS
T0866

Exploitation of Remote Services

Description

Adversaries may exploit a software vulnerability to take advantage of a programming error in a program, service, or within the operating system software or kernel itself to enable remote service abuse. A common goal for post-compromise exploitation of remote services is for initial access into and lateral movement throughout the ICS environment to enable access to targeted systems. (Citation: Enterprise ATT&CK) ICS asset owners and operators have been affected by ransomware (or disruptive malware masquerading as ransomware) migrating from enterprise IT to ICS environments: WannaCry, NotPetya, and BadRabbit. In each of these cases, self-propagating (wormable) malware initially infected IT networks, but through exploit (particularly the SMBv1-targeting MS17-010 vulnerability) spread to industrial networks, producing significant impacts. (Citation: Joe Slowik April 2019)

Mapped SPARTA techniques

2 techniques

  • LM-0001Hosted PayloadST0007
    addresses
    moderate

    T0866 'Exploitation of Remote Services' is in MITRE ICS lateral-movement tactic and addresses exploiting vulnerabilities in remote services to move laterally; SPARTA LM-0001 'Hosted Payload' covers payload-to-bus pivot which exploits the payload-bus interface as the remote service granting cross-partition movement. Tactic and activity align directly.

  • Exploiting lack of bus segregation lets the adversary traverse subsystems via unsegregated bus paths — exact instance of T0866 'Exploitation of Remote Services' applied to inter-subsystem bus interfaces. Tactic and activity align (lateral-movement).

Cite as SafeMode Space, mitre-attack-ics T0866.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.