T1021.006 - Windows Remote Management - MITRE ATT&CK

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
April 20, 2026
Last Seen
July 6, 2026

T1021.006 - Windows Remote Management is a mitre_attack tracked across 3 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed April 20, 2026; most recent activity July 6, 2026.

Related Threat Clusters

  • Exploitation of Remote Services in Cyber Attacks

    Adversaries are increasingly leveraging external remote services like VPNs and Citrix to gain unauthorized access to networks. These attacks often involve using valid accounts obtained through credential harvesting or…

    2 articles · Updated June 3, 2026
  • Gentlemen Ransomware Uses Advanced Techniques for Network Attacks

    The Gentlemen ransomware, a Go-based RaaS, has been active since mid-2025 and employs aggressive propagation methods. It utilizes 21 remote execution techniques, including PsExec, WMIC, and PowerShell Remoting, to…

    3 articles · Updated July 6, 2026
  • Microsoft Teams Exploited for Helpdesk Impersonation Attacks

    Cyber attackers are increasingly using Microsoft Teams to impersonate IT helpdesk staff, employing social engineering tactics to gain remote access to enterprise systems. This method, known as 'cross-tenant helpdesk…

    51 articles · Updated April 20, 2026

Recent Intelligence Reports

  • Go-Based Gentlemen Ransomware Uses PsExec, WMIC, and PowerShell Remoting for ... — Gbhackers · July 6, 2026
  • External Remote Services — attack.mitre.org · June 3, 2026
  • Microsoft: Teams increasingly abused in helpdesk impersonation attacks — Bleepingcomputer · April 20, 2026

CVSS v3.1 Breakdown