Real-world descriptions of how a group, tool or campaign used a technique.
62 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1486 Data Encrypted for Impact |
MalwareREvil | REvil can encrypt files on victim systems and demands a ransom to decrypt the files. |
| T1486 Data Encrypted for Impact |
MalwareROADSWEEP | ROADSWEEP can RC4 encrypt content in blocks on targeted systems. |
| T1486 Data Encrypted for Impact |
MalwareClop | Clop can encrypt files using AES, RSA, and RC4 and will add the ".clop" extension to encrypted files. |
| T1486 Data Encrypted for Impact |
MalwareEgregor | Egregor can encrypt all non-system files using a hybrid AES-RSA algorithm prior to displaying a ransom note. |
| T1486 Data Encrypted for Impact |
MalwareMaze | Maze has disrupted systems by encrypting files on targeted machines, claiming to decrypt files if a ransom payment is made. Maze has used the ChaCha algorithm, based on Salsa20, and an RSA algorithm to encrypt files. |
| T1486 Data Encrypted for Impact |
MalwareXCSSET | XCSSET performs AES-CBC encryption on files under |
| T1486 Data Encrypted for Impact |
MalwareKillDisk | KillDisk has a ransomware component that encrypts files with an AES key that is also RSA-1028 encrypted. |
| T1486 Data Encrypted for Impact |
MalwareQilin | Qilin can use AES-256 or ChaCha20 for domain-wide encryption of victim servers and workstations and RSA-4096 or RSA-2048 to secure generated encryption keys. |
| T1486 Data Encrypted for Impact |
MalwareINC Ransomware | INC Ransomware can encrypt data on victim systems, including through the use of partial encryption and multi-threading to speed encryption. |
| T1486 Data Encrypted for Impact |
MalwareFIVEHANDS | FIVEHANDS can use an embedded NTRU public key to encrypt data for ransom. |
| T1486 Data Encrypted for Impact |
MalwareSeth-Locker | Seth-Locker can encrypt files on a targeted system, appending them with the suffix .seth. |
| T1486 Data Encrypted for Impact |
MalwareBitPaymer | BitPaymer can import a hard-coded RSA 1024-bit public key, generate a 128-bit RC4 key for each file, and encrypt the file in place, appending |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.