S0500: MCMD
MITRE ATT&CK S0500: MCMD Tool details for Windows, with detection guidance, relationships and mapped CVEs.
Security context for executives and security teams
MCMD is a Windows remote access tool with remote command shell capability, documented by ATT&CK as used by Dragonfly. Its decision value is that a single implant can combine command execution, persistence, stealth, web-based command-and-control, tool transfer, and local data access, so defenders should not treat it as only a malware signature problem.
Executive priority
Prioritize MCMD as a readiness test for Windows endpoint visibility, incident response triage, and resilience in environments where Dragonfly-relevant risk matters, including government, defense, aviation, industrial control system, and critical infrastructure contexts referenced in the related group description. Leaders should ask whether teams can prove visibility into persistence creation, command shell activity, outbound web-protocol C2, and cleanup of persistence artifacts—not just whether an antivirus name is detected.
Technical view
ATT&CK provides no official detection text for MCMD, so coverage should be validated through the related behaviors: Windows Command Shell, Scheduled Task, Registry Run Keys/Startup Folder, Hidden Window, Obfuscated Files or Information, Match Legitimate Resource Name or Location, Clear Persistence, Web Protocols, Ingress Tool Transfer, and Data from Local System. SOC and IR teams should correlate suspicious cmd.exe activity with new or modified scheduled tasks, Run key/startup entries, unusual file placement or naming, hidden execution patterns, tool downloads, local data access, and outbound HTTP/S-like traffic from uncommon processes.
Likely telemetry
- Windows endpoint process creation telemetry with command line, parent/child process, user, and integrity context
- Windows Task Scheduler creation, modification, execution, and deletion events
- Registry monitoring for Run keys and startup-folder persistence paths
- File creation, modification, deletion, and rename telemetry, especially for suspicious placement or legitimate-looking names
- Endpoint alerts or logs showing obfuscated, packed, encoded, or otherwise hard-to-analyze files
Detection direction
- Because ATT&CK lists no official MCMD detection guidance, validate behavior-based analytics rather than relying only on malware family names.
- Tune for suspicious command shell activity that is remote, automated, or spawned by unusual parent processes, while accounting for legitimate administration tools.
- Correlate scheduled task and Run key creation with nearby command execution, new binaries, outbound web traffic, or file transfer events.
- Hunt for executables placed in trusted-looking locations or named to resemble legitimate resources, especially when paired with hidden-window execution or obfuscation indicators.
- Monitor for persistence artifacts that are created and later removed, since Clear Persistence can reduce the evidence available during incident response.
Mitigation priorities
- Confirm Windows endpoint logging and EDR coverage for process, registry, task scheduler, file, and network activity before assuming MCMD-like behavior is observable.
- Harden and monitor persistence locations such as Run keys, startup folders, and scheduled tasks with change control and alerting.
- Apply least privilege so ordinary user contexts have limited ability to establish durable persistence or access sensitive local data.
- Restrict and inspect outbound web-protocol traffic where feasible, especially from servers and administrative workstations that should not initiate broad external connections.
- Maintain incident response procedures for rapid collection of volatile process, persistence, file, and network evidence before cleanup activity removes artifacts.
Additional notes and limits
The supplied ATT&CK relationship context is the main source of practical defensive value: MCMD is a Windows remote access tool used by Dragonfly and linked to execution, persistence, stealth, command-and-control, tool transfer, and local data behaviors. The Dragonfly relationship makes this especially relevant for organizations assessing espionage-oriented risk and critical infrastructure/ICS-adjacent exposure, but local prioritization should be based on actual environment, assets, and telemetry.
No official ATT&CK detection text, aliases, or tactics are supplied for the MCMD software object. Several behavior details come from relationships rather than the software description itself. This take does not assert current activity, customer exposure, guaranteed detection, or platform scope beyond the supplied Windows platform for MCMD and the listed related techniques.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
MCMD
No official description is available in the imported ATT&CK source object.
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
All related ATT&CK context
No relationships are available in the current normalized data for this object.
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
