What is lateral movement?

Lateral movement is the phase of a cyberattack in which an attacker, having compromised a first system, uses stolen credentials and legitimate administration tools to hop from system to system within a network until they reach their actual target. In industrial environments that target is nearly always the same: the step from the corporate network (IT) to process control (OT). Most well-known attacks on factories and power grids did not start inside the OT; they began with a phishing email or a VPN account and then moved sideways.


🧠 Where does lateral movement sit in the kill chain?

Lockheed Martin’s classic Cyber Kill Chain (2011) has seven steps, from reconnaissance to actions on objectives. Lateral movement belongs to that last phase: the attacker is inside and is expanding their foothold. For industrial systems, Michael Assante and Robert M. Lee extended this at SANS in 2015 into the ICS Cyber Kill Chain, which has two stages:

  • Stage 1 β€” intrusion into the IT network, including the pivot from the corporate network into the ICS or OT segments
  • Stage 2 β€” developing, testing and executing an attack that affects the physical process itself

Lateral movement is therefore the hinge between the two stages. In MITRE ATT&CK the tactic has its own identifier: TA0008 in the Enterprise matrix and TA0109 in MITRE ATT&CK for ICS.

Framework Where lateral movement sits
Lockheed Martin Cyber Kill Chain Within actions on objectives, after installation and command & control
SANS ICS Cyber Kill Chain End of stage 1: the pivot from IT into OT
MITRE ATT&CK Enterprise Tactic TA0008 Lateral Movement
MITRE ATT&CK for ICS Tactic TA0109 Lateral Movement

πŸ”§ Which techniques do attackers use?

What stands out is that most techniques need no exploit at all. Attackers live off the land: they use the administration tools already present on the network, with genuine accounts.

Technique How it works ATT&CK ID
RDP Logging on to a server or HMI with stolen credentials T1021.001
SMB / PsExec Copying files and starting services through admin shares T1021.002
WMI / WinRM Running commands remotely without custom malware T1047 / T1021.006
Pass-the-hash / pass-the-ticket Authenticating with a captured hash or Kerberos ticket instead of a password T1550.002 / .003
Stolen or default passwords Valid accounts, or factory passwords on OT devices T0859 / T0812 (ICS)
Jump host abuse Reaching the control network directly through an over-privileged jump server T0886 (ICS)
Dual-homed hosts A PC or historian with one network card in IT and one in OT, bypassing the firewall β€”
Engineering workstation Downloading a new PLC program from the engineering station T0843 (ICS)
Shared Active Directory One domain for IT and OT: whoever is domain admin also owns the OT T1078
VPN pivot Moving deeper into the network from a hijacked VPN session T1133

With a shared Active Directory, the domain controller is the crown jewel. An attacker who reaches it can log on in one go to every Windows system in the plant, from SCADA server to operator station.


🏭 Which attacks showed lateral movement into OT?

  • Ukraine, 23 December 2015 β€” the attackers had been inside for more than six months, having entered through phishing emails carrying BlackEnergy 3. They harvested credentials, took over the directory services and used those accounts to log on through the VPN to the SCADA network, which had no two-factor authentication. They then used the utilities’ own SCADA software to open circuit breakers; around 225,000 customers lost power for up to six hours. The operation is attributed to Sandworm.
  • NotPetya, 27 June 2017 β€” started with a poisoned update of the Ukrainian accounting package M.E.Doc. The wiper then spread within minutes using the SMBv1 exploits EternalBlue and EternalRomance, plus a modified Mimikatz that pulled passwords from memory and passed them to PsExec and WMIC. Factories came to a standstill because their Windows systems sat on the same network.
  • Colonial Pipeline, May 2021 β€” the DarkSide ransomware group got in on 29 April through a legacy VPN account without MFA. The OT was not hit, but because the company could not rule out further movement, it shut down the entire pipeline as a precaution on 7 May. It did not restart until 12 May.
  • Volt Typhoon β€” according to a CISA advisory of February 2024, this Chinese state-sponsored group spent years inside the IT networks of critical infrastructure operators, moved to domain controllers using valid administrator accounts and RDP, and pre-positioned itself for a later step into OT.

πŸ” How do you detect lateral movement?

Because attackers use legitimate tools, lateral movement rarely triggers classic antivirus. Detection is about behaviour:

  • OT network monitoring β€” a passive IDS on a mirror port learns which system normally talks to which PLC. A new RDP session to an HMI, or a program download outside a maintenance window, stands out immediately.
  • East-west traffic β€” watch not only traffic crossing the boundary (north-south) but also traffic between systems in the same zone. An operator station opening SMB connections to ten other stations is suspicious.
  • Honeypots and deception β€” nobody has a legitimate reason to touch a decoy PLC or fake file share in the OT segment. Any connection to a honeypot is therefore an alert with very few false positives.
  • Log correlation β€” Windows events such as 4624 (logon, with type 3 for network and type 10 for RDP), 4648 (logon with explicit credentials) and 7045 (new service installed, typical of PsExec), combined in a SIEM, reveal when one account suddenly appears on many systems.

πŸ” How do you prevent lateral movement into OT?

The principle is simple: a successful intrusion into IT must not automatically mean access to OT.

  • Network segmentation per IEC 62443 β€” divide the installation into zones and conduits according to the zones and conduits model. IEC 62443-3-3 captures this in foundational requirement FR 5 Restricted Data Flow, with SR 5.1 (network segmentation) and SR 5.2 (zone boundary protection, enhanced with deny by default, allow by exception).
  • An IDMZ between IT and OT β€” no connection runs straight from the office to the control network; data passes through an intermediate layer holding historian replicas and patch servers.
  • A separate AD forest for OT β€” with no trust to the corporate domain, so a compromised IT domain admin has no power in the plant.
  • MFA on all external access β€” VPN, remote access and the jump server; this would have made both Ukraine 2015 and Colonial Pipeline considerably harder.
  • PAM β€” privileged accounts are issued per session, recorded and revoked afterwards; local administrator passwords are unique per system.
  • Application whitelisting β€” HMIs and servers run only approved software, so PsExec or Mimikatz simply will not start.
  • Microsegmentation β€” even within a zone, allow only the connections the process genuinely needs.

πŸ› οΈ How do you tackle it step by step?

  1. Map the paths β€” inventory every connection between IT and OT: VPNs, remote access portals, dual-homed PCs, shared accounts and vendor connections.
  2. Close dual-homed hosts and direct routes β€” every connection goes through the IDMZ or a managed jump server.
  3. Separate identities β€” a separate AD forest or local accounts for OT, and no password reuse between domains.
  4. Enforce MFA and PAM β€” first on all external access, then on administrative accounts inside the OT.
  5. Restrict admin protocols β€” block SMB, RDP and WinRM between workstations; allow them only from the jump server.
  6. Monitor east-west traffic β€” deploy an OT IDS, feed Windows logging into a SIEM and place a few honeypots.
  7. Rehearse β€” run a scenario in which the IT domain controller has been taken over: can the OT keep running, or would you have to stop, as Colonial Pipeline did?

❓ Frequently asked questions

What is the difference between lateral movement and privilege escalation?

Privilege escalation means gaining higher rights on the same system, for example from ordinary user to administrator. Lateral movement means moving to other systems on the network. In practice the two alternate: higher privileges yield new credentials, which the attacker then uses for further lateral movement.

Why is lateral movement so hard to detect?

Lateral movement often relies on the same tools and accounts that real administrators use, such as RDP, PsExec and PowerShell. There is no malware to find, only unusual behaviour. Detecting it therefore requires a clear baseline of normal traffic and log correlation across many systems.

Is network segmentation enough to stop lateral movement?

Segmentation greatly limits lateral movement, but it is not enough if the permitted paths can be abused. A shared Active Directory or a jump server without MFA still lets an attacker in through a legitimate conduit. Segmentation only becomes truly effective combined with separate identities, MFA and monitoring.

Which MITRE ATT&CK tactic covers lateral movement?

In the MITRE ATT&CK Enterprise matrix, lateral movement is tactic TA0008, with techniques such as Remote Services and Use Alternate Authentication Material. In MITRE ATT&CK for ICS it is TA0109, including Valid Accounts, Remote Services and Program Download. Together they describe the route from the office network to the PLC.

How long does lateral movement take?

The duration of lateral movement ranges from minutes to years. NotPetya spread automatically through entire corporate networks within minutes, whereas the attackers in Ukraine in 2015 took months and Volt Typhoon remained undetected for years according to CISA. The slower and quieter the attacker, the more important behavioural detection becomes.

Does lateral movement matter in attacks that only hit IT?

Yes, even in ransomware that only hits IT, lateral movement is why a single infected laptop can bring down a whole company. That matters to OT teams because processes often depend on IT systems such as planning, invoicing or the historian. Production can then stop even without any direct infection of the OT.


πŸ“Œ In summary

Lateral movement is the step in which an office intrusion grows into a threat to the physical process. Attackers rarely need exotic exploits for it; they rely on stolen passwords, shared domains, VPNs without MFA and ordinary admin tools. Separating IT and OT into zones and conduits, decoupling identities and watching east-west traffic makes that step both difficult and visible.

Lateral movement decides whether an IT incident becomes an OT incident: segment, separate identities and make every connection between office and plant controllable.