Skip to content
Threat Feed
medium advisory

Monitoring Unauthorized Telnet Usage for Lateral Movement

Adversaries may abuse the Telnet protocol to move laterally within a network, necessitating monitoring of internal Telnet connections to identify unauthorized remote access attempts.

Telnet is a legacy protocol that provides a command-line interface for remote device management. Because it transmits data, including credentials, in cleartext and is often used for legitimate remote administration, it remains a target for adversaries seeking to move laterally within a network. Threat actors exploit Telnet to connect to non-public, internal IP addresses to execute arbitrary commands or exfiltrate sensitive data.

Defenders should note that while Telnet is included by default in various Linux distributions, its usage has declined significantly in favor of more secure protocols like SSH. Consequently, any unmonitored or non-automated Telnet activity, particularly involving connections to internal subnets, is considered potentially malicious. Organizations should focus on identifying deviations from established administrative baselines and auditing the source processes initiating these connections.

Impact

Successful exploitation of Telnet for lateral movement allows unauthorized remote access to internal network segments. This enables attackers to move deeper into the environment, potentially compromising additional systems, executing commands with elevated privileges, or facilitating data exfiltration. Given the protocol's lack of encryption, intercepted sessions expose administrative credentials, further expanding the scope of the compromise.

Recommendation

Prioritize the identification and auditing of all Telnet activity within the internal network to distinguish between legacy administrative tasks and potential adversarial movement.

  • Deploy the provided Sigma detection rule to flag Telnet connections targeting non-publicly routable internal IP addresses.
  • Implement network segmentation to restrict Telnet access to specific, required systems and decommission the protocol on all other hosts.
  • Establish a whitelist of legitimate Telnet-based administrative tools or scripts to reduce false-positive alerts.
  • Isolate hosts exhibiting unauthorized Telnet activity immediately to prevent further lateral movement and rotate all credentials associated with the compromised host.

Immediate actions

Deploy Sigma detection rule to SIEM

Detection Engineering 24h

Threat Hunt

Identify all processes executing telnet to internal CIDR ranges

T1021 high high confidence hunt now

Data: Process command line and network connection logs

Mitigations

Disable Telnet and transition to SSH for remote management

medium_term IT Operations

Legacy protocol exploitation

Detection coverage 1

Detect Internal Network Connection via Telnet

medium

Detects Telnet process initiation followed by a network connection to non-public/internal IP ranges, which may indicate lateral movement

sigma tactics: lateral_movement techniques: T1021 sources: process_creation, linux

Detection queries are available on the platform. Get full rules →