TACTIC: LATERAL MOVEMENT
SMB / Windows Admin Shares (T1021.002): real cases
MITRE Definition ↗ Adversaries leverage Server Message Block (SMB) and administrative shares (C$, ADMIN$) for lateral spread.
Key Facts
Technique ID
T1021.002
Lateral Movement
Mapped Cases
2
Primary sources
Related Laws
4
Criminal statutes
- ATT&CK Technique Identifier: T1021.002.
- Tactical Phase: Lateral Movement.
- Substantiated in 2 primary court prosecution cases.
- Every associated case includes verbatim evidentiary excerpts from indictments or sworn affidavits.
Verified Evidentiary Case Records
U.S. v. Andrienko et al. (Sandworm / GRU Unit 74455)
fugitive 2020-10-15
Primary Source Evidence Excerpt: Indictment ¶ 47, Page 24
"NotPetya leveraged EternalBlue (MS17-010) over SMB and PsExec to rapidly propagate across internal network subnets without user intervention."
U.S. District Court for the Western District of Pennsylvania
View full case dossier →
U.S. v. Park Jin Hyok (Lazarus Group / Chosun Expo)
fugitive 2018-06-08
Primary Source Evidence Excerpt: Criminal Complaint ¶ 92, Page 64
"WannaCry automated its spread using the EternalBlue SMB exploit code to compromise unpatched Windows servers."
U.S. District Court for the Central District of California
View full case dossier →
Commonly Charged Criminal Statutes
18 U.S.C. § 1030(a)(2)
Unauthorized Access to Obtain Protected Information
Prohibits intentionally accessing a computer without authorization or exceeding authorized access to obtain financial, government, or protected computer records.
18 U.S.C. § 1030(a)(5)(A)
Intentional Damage to a Protected Computer
Prohibits knowingly causing the transmission of a program, information, code, or command that intentionally causes damage without authorization to a protected computer.
18 U.S.C. § 1030(a)(7)
Extortion in Connection with Computers
Prohibits transmitting in interstate or foreign commerce threats to cause damage to a protected computer or obtain confidential information with intent to extort money or value.
18 U.S.C. § 1030(b)
Conspiracy to Commit Computer Fraud
Punishes any person who conspires to commit or attempts to commit any computer fraud offense under section 1030.