MITRE ATT&CK T1021.001 Remote Services: RDP refers to adversaries leveraging Remote Desktop Protocol to access and control a remote Windows host, enabling initial access, lateral movement, and potential persistence.
Overview
MITRE ATT&CK T1021.001 Remote Services: RDP refers to adversaries leveraging Remote Desktop Protocol to access and control a remote Windows host, enabling initial access, lateral movement, and potential persistence. It remains a high-risk vector due to widespread RDP exposure, misconfigurations, and weak credentials, making robust authentication, network segmentation, and monitoring critical for defense.
Related Threat Clusters
-
Chinese-Speaking Threat Actors Exploit VMware ESXi via Compromised SonicWall VPN
In December 2025, Chinese-speaking threat actors exploited vulnerabilities in VMware ESXi using a toolkit delivered through a compromised SonicWall VPN appliance. The toolkit included exploits for three zero-day…
2 articles · Updated January 8, 2026
Recent Intelligence Reports
- VMware ESXi zero — Bleepingcomputer · January 8, 2026