ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1486×

62 examples

TechniqueUsed byProcedure example
T1486
Data Encrypted for Impact
MalwareREvil

REvil can encrypt files on victim systems and demands a ransom to decrypt the files.

T1486
Data Encrypted for Impact
MalwareROADSWEEP

ROADSWEEP can RC4 encrypt content in blocks on targeted systems.

T1486
Data Encrypted for Impact
MalwareClop

Clop can encrypt files using AES, RSA, and RC4 and will add the ".clop" extension to encrypted files.

T1486
Data Encrypted for Impact
MalwareEgregor

Egregor can encrypt all non-system files using a hybrid AES-RSA algorithm prior to displaying a ransom note.

T1486
Data Encrypted for Impact
MalwareMaze

Maze has disrupted systems by encrypting files on targeted machines, claiming to decrypt files if a ransom payment is made. Maze has used the ChaCha algorithm, based on Salsa20, and an RSA algorithm to encrypt files.

T1486
Data Encrypted for Impact
MalwareXCSSET

XCSSET performs AES-CBC encryption on files under ~/Documents, ~/Downloads, and
~/Desktop with a fixed key and renames files to give them a .enc extension. Only files with sizes
less than 500MB are encrypted.

T1486
Data Encrypted for Impact
MalwareKillDisk

KillDisk has a ransomware component that encrypts files with an AES key that is also RSA-1028 encrypted.

T1486
Data Encrypted for Impact
MalwareQilin

Qilin can use AES-256 or ChaCha20 for domain-wide encryption of victim servers and workstations and RSA-4096 or RSA-2048 to secure generated encryption keys.

T1486
Data Encrypted for Impact
MalwareINC Ransomware

INC Ransomware can encrypt data on victim systems, including through the use of partial encryption and multi-threading to speed encryption.

T1486
Data Encrypted for Impact
MalwareFIVEHANDS

FIVEHANDS can use an embedded NTRU public key to encrypt data for ransom.

T1486
Data Encrypted for Impact
MalwareSeth-Locker

Seth-Locker can encrypt files on a targeted system, appending them with the suffix .seth.

T1486
Data Encrypted for Impact
MalwareBitPaymer

BitPaymer can import a hard-coded RSA 1024-bit public key, generate a 128-bit RC4 key for each file, and encrypt the file in place, appending .locked to the filename.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.