Remote Services
Description
Adversaries may leverage remote services to move between assets and network segments. These services are often used to allow operators to interact with systems remotely within the network, some examples are RDP, SMB, SSH, and other similar mechanisms. (Citation: Blake Johnson, Dan Caban, Marina Krotofil, Dan Scali, Nathan Brubaker, Christopher Glyer December 2017) (Citation: Dragos December 2017) (Citation: Joe Slowik April 2019) Remote services could be used to support remote access, data transmission, authentication, name resolution, and other remote functions. Further, remote services may be necessary to allow operators and administrators to configure systems within the network from their engineering or management workstations. An adversary may use this technique to access devices which may be dual-homed (Citation: Blake Johnson, Dan Caban, Marina Krotofil, Dan Scali, Nathan Brubaker, Christopher Glyer December 2017) to multiple network segments, and can be used for [Program Download](https://attack.mitre.org/techniques/T0843) or to execute attacks on control devices directly through [Valid Accounts](https://attack.mitre.org/techniques/T0859). Specific remote services (RDP & VNC) may be a precursor to enable [Graphical User Interface](https://attack.mitre.org/techniques/T0823) execution on devices such as HMIs or engineering workstation software. Based on incident data, CISA and FBI assessed that Chinese state-sponsored actors also compromised various authorized remote access channels, including systems designed to transfer data and/or allow access between corporate and ICS networks. (Citation: CISA AA21-201A Pipeline Intrusion July 2021)
Mapped SPARTA techniques
8 techniques
T0886 'Remote Services' is in ATT&CK ICS initial-access tactic and addresses adversary use of legitimate remote-service mechanisms for cross-system access; SPARTA IA-0003 'Crosslink via Compromised Neighbor' uses the inter-satellite link as a legitimate remote-service path for cross-vehicle initial access. Tactic and activity align.
Hosted-payload-to-bus pivot uses the legitimate payload-bus interface as a remote-service path; T0886 'Remote Services' covers this pattern at cross-domain moderate (payload-bus boundary as remote-service equivalent in spacecraft context).
After compromising a valid ground system, the adversary uses its legitimate remote-service connectivity to issue commands — T0886 'Remote Services' covers this initial-access pattern via legitimate/abused remote-service mechanisms. Tactic and activity align.
Compromising the host spacecraft to attack a hosted payload uses the legitimate host-payload interface as a remote-service path (the host has trusted access to the payload partition); T0886 'Remote Services' covers this cross-direction pattern at moderate confidence (cross-domain — host-payload boundary as remote-service equivalent).
T0886 'Remote Services' is in MITRE ICS lateral-movement tactic and addresses lateral movement via legitimate remote-service mechanisms; SPARTA LM-0003 covers constellation-hopping via crosslink — using the legitimate inter-satellite-link as the remote service for cross-vehicle lateral movement. Tactic and activity align directly.
Visiting-vehicle interfaces (docking ports, RPO data links, OSAM cooperative interfaces) function as remote services granting lateral access between vehicles — direct instance of T0886 'Remote Services' for cross-vehicle lateral movement. Tactic-aligned.
Launch-vehicle-to-spacecraft interfaces (separation connectors, pre-separation data buses, integration ports) are remote services granting cross-vehicle access during the pre-separation phase — direct instance of T0886 'Remote Services' applied to launch-vehicle interfaces.
Rideshare payload pivoting via shared launch-vehicle interface or shared upper-stage data bus uses the rideshare-mate's connectivity as a remote service for lateral movement — direct instance of T0886 'Remote Services' applied to rideshare-shared interfaces.
Cite as SafeMode Space, mitre-attack-ics T0886.