LiveActive security incident?Get immediate response
MITRE ATT&CK® Tool

S0500: MCMD

MITRE ATT&CK S0500: MCMD Tool details for Windows, with detection guidance, relationships and mapped CVEs.

EnterpriseS0500ToolObject v1.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

MCMD is a Windows remote access tool with remote command shell capability, documented by ATT&CK as used by Dragonfly. Its decision value is that a single implant can combine command execution, persistence, stealth, web-based command-and-control, tool transfer, and local data access, so defenders should not treat it as only a malware signature problem.

Executive priority

Prioritize MCMD as a readiness test for Windows endpoint visibility, incident response triage, and resilience in environments where Dragonfly-relevant risk matters, including government, defense, aviation, industrial control system, and critical infrastructure contexts referenced in the related group description. Leaders should ask whether teams can prove visibility into persistence creation, command shell activity, outbound web-protocol C2, and cleanup of persistence artifacts—not just whether an antivirus name is detected.

Technical view

ATT&CK provides no official detection text for MCMD, so coverage should be validated through the related behaviors: Windows Command Shell, Scheduled Task, Registry Run Keys/Startup Folder, Hidden Window, Obfuscated Files or Information, Match Legitimate Resource Name or Location, Clear Persistence, Web Protocols, Ingress Tool Transfer, and Data from Local System. SOC and IR teams should correlate suspicious cmd.exe activity with new or modified scheduled tasks, Run key/startup entries, unusual file placement or naming, hidden execution patterns, tool downloads, local data access, and outbound HTTP/S-like traffic from uncommon processes.

Likely telemetry

  • Windows endpoint process creation telemetry with command line, parent/child process, user, and integrity context
  • Windows Task Scheduler creation, modification, execution, and deletion events
  • Registry monitoring for Run keys and startup-folder persistence paths
  • File creation, modification, deletion, and rename telemetry, especially for suspicious placement or legitimate-looking names
  • Endpoint alerts or logs showing obfuscated, packed, encoded, or otherwise hard-to-analyze files

Detection direction

  • Because ATT&CK lists no official MCMD detection guidance, validate behavior-based analytics rather than relying only on malware family names.
  • Tune for suspicious command shell activity that is remote, automated, or spawned by unusual parent processes, while accounting for legitimate administration tools.
  • Correlate scheduled task and Run key creation with nearby command execution, new binaries, outbound web traffic, or file transfer events.
  • Hunt for executables placed in trusted-looking locations or named to resemble legitimate resources, especially when paired with hidden-window execution or obfuscation indicators.
  • Monitor for persistence artifacts that are created and later removed, since Clear Persistence can reduce the evidence available during incident response.

Mitigation priorities

  • Confirm Windows endpoint logging and EDR coverage for process, registry, task scheduler, file, and network activity before assuming MCMD-like behavior is observable.
  • Harden and monitor persistence locations such as Run keys, startup folders, and scheduled tasks with change control and alerting.
  • Apply least privilege so ordinary user contexts have limited ability to establish durable persistence or access sensitive local data.
  • Restrict and inspect outbound web-protocol traffic where feasible, especially from servers and administrative workstations that should not initiate broad external connections.
  • Maintain incident response procedures for rapid collection of volatile process, persistence, file, and network evidence before cleanup activity removes artifacts.
Additional notes and limits

The supplied ATT&CK relationship context is the main source of practical defensive value: MCMD is a Windows remote access tool used by Dragonfly and linked to execution, persistence, stealth, command-and-control, tool transfer, and local data behaviors. The Dragonfly relationship makes this especially relevant for organizations assessing espionage-oriented risk and critical infrastructure/ICS-adjacent exposure, but local prioritization should be based on actual environment, assets, and telemetry.

No official ATT&CK detection text, aliases, or tactics are supplied for the MCMD software object. Several behavior details come from relationships rather than the software description itself. This take does not assert current activity, customer exposure, guaranteed detection, or platform scope beyond the supplied Windows platform for MCMD and the listed related techniques.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

MCMD

No official description is available in the imported ATT&CK source object.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.1
Created
Modified
Raw hash
db48ec06fde22910...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.