USENIX Security2020Top-tier venue
ShadowMove: A Stealthy Lateral Movement Strategy
Amirreza Niakanlahiji, Jinpeng Wei, Md Rabbi Alam, Qingyang Wang, Bei-Tseng Chu
Abstract
Advanced Persistence Threat (APT) attacks use various strategies and techniques to move laterally within an enterprise environment; however, the existing strategies and techniques have limitations such as requiring elevated permissions, creating new connections, performing new authentications, or requiring process injections. Based on these characteristics, many host and network-based solutions have been proposed to prevent or detect such lateral movement attempts. In this paper, we present a novel stealthy lateral movement strategy, ShadowMove, in which only established connections between systems in an enterprise network are misused for lateral movements. It has a set of unique features such as requiring no elevated privilege, no new connection, no extra authentication, and no process injection, which makes it stealthy against stateof-the-art detection mechanisms. ShadowMove is enabled by a novel socket duplication approach that allows a malicious process to silently abuse TCP connections established by benign processes. We design and implement ShadowMove for current Windows and Linux operating systems. To validate the feasibility of ShadowMove, we build several prototypes that successfully hijack three kinds of enterprise protocols, FTP, Microsoft SQL, and Window Remote Management, to perform lateral movement actions such as copying malware to the next target machine and launching malware on the target machine. We also confirm that our prototypes cannot be detected by existing host and network-based solutions, such as five top-notch anti-virus products (McAfee, Norton, Webroot, Bitdefender, and Windows Defender), four IDSes (Snort, OS-SEC, Osquery, and Wazuh), and two Endpoint Detection and Response systems (CrowdStrike Falcon Prevent and Cisco AMP).
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers4
- Hopper: Modeling and Detecting Lateral MovementGrant Ho, Mayank Dhiman, Devdatta Akhawe, Vern Paxson et al.USENIX Security 2021 · 41 citations
- Understanding and Bridging the Gap Between Unsupervised Network Representation Learning and Security AnalyticsJiacen Xu, Xiaokui Shu, Zhou LiS&P 2024 · 14 citations
- How does Endpoint Detection use the MITRE ATT&CK Framework?Apurva Virkud, Muhammad Adil Inam, Andy Riddle, Jason Liu et al.USENIX Security 2024 · 9 citations
- Hop: A Modern Transport and Remote Access ProtocolPaul Flammarion, George Hosono, Wilson Nguyen, Laura Bauman et al.USENIX Security 2026
Builds on4
- Detecting Structurally Anomalous Logins Within Enterprise NetworksHossein Siadati, Nasir D. MemonCCS 2017 · 44 citations
- Off-Path TCP Exploit: How Wireless Routers Can Jeopardize Your SecretsWeiteng Chen, Zhiyun QianUSENIX Security 2018 · 35 citations
- Man-in-the-Machine: Exploiting Ill-Secured Communication Inside the ComputerThanh Bui, Siddharth Prakash Rao, Markku Antikainen, Viswanathan Manihatty Bojan et al.USENIX Security 2018 · 25 citations
- The Secure Socket API: TLS as an Operating System ServiceMark O'Neill, Scott Heidbrink, Jordan Whitehead, Tanner Perdue et al.USENIX Security 2018 · 20 citations
Related papers
- You Are What You Do: Hunting Stealthy Malware via Data Provenance AnalysisQi Wang, Wajih Ul Hassan, Ding Li, Kangkook Jee et al.NDSS 2020
- Jbeil: Temporal Graph-Based Inductive Learning to Infer Lateral Movement in Evolving Enterprise NetworksJoseph Khoury, Dorde Klisura, Hadi Zanddizari, Gonzalo De La Torre Parra et al.S&P 2024 · 28 citations
- EvilEDR: Repurposing EDR as an Offensive ToolKotaiba Alachkar, Dirk Gaastra, Eduardo Barbaro, Michel van Eeten et al.USENIX Security 2025
- Slot: Provenance-Driven APT Detection through Graph Reinforcement LearningWei Qiao, Yebo Feng, Teng Li, Zhuo Ma et al.CCS 2025 · 1 citation
- Unicorn: Runtime Provenance-Based Detector for Advanced Persistent ThreatsXueyuan Han, Thomas F. J.-M. Pasquier, Adam Bates, James Mickens et al.NDSS 2020
