Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1486 Data Encrypted for Impact |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors deployed ransomware including 4L4MD4R and Warlock. |
| T1486 Data Encrypted for Impact |
CampaignC0018 | During C0018, the threat actors used AvosLocker ransomware to encrypt files on the compromised network. |
| T1486 Data Encrypted for Impact |
CampaignC0015 | During C0015, the threat actors used Conti ransomware to encrypt a compromised network. |
| T1486 Data Encrypted for Impact |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used ROADSWEEP ransomware to encrypt files on targeted systems. |
| T1486 Data Encrypted for Impact |
GroupAPT38 | APT38 has used Hermes ransomware to encrypt files with AES256. |
| T1486 Data Encrypted for Impact |
GroupIndrik Spider | Indrik Spider has encrypted domain-controlled systems using BitPaymer. Additionally, Indrik Spider used PsExec to execute a ransomware script. |
| T1486 Data Encrypted for Impact |
GroupBlackByte | BlackByte has encrypted victim files for ransom. Early versions of BlackByte ransomware used a common key for encryption, but later versions use unique keys per victim. |
| T1486 Data Encrypted for Impact |
GroupAPT41 | APT41 used a ransomware called Encryptor RaaS to encrypt files on the targeted systems and provide a ransom note to the user. APT41 also used Microsoft Bitlocker to encrypt workstations and Jetico’s BestCrypt to encrypt servers. |
| T1486 Data Encrypted for Impact |
GroupStorm-1811 | Storm-1811 is a financially-motivated entity linked to the deployment of Black Basta ransomware in victim environments. |
| T1486 Data Encrypted for Impact |
GroupFIN7 | FIN7 has encrypted virtual disk volumes on ESXi servers using a version of Darkside ransomware. Additionally, FIN7 has deployed ransomware as the end payload during big game hunting. |
| T1486 Data Encrypted for Impact |
GroupSandworm Team | Sandworm Team has used Prestige ransomware to encrypt data at targeted organizations in transportation and related logistics industries in Ukraine and Poland. |
| T1486 Data Encrypted for Impact |
GroupScattered Spider | Scattered Spider has used BlackCat and DragonForce ransomware to encrypt files including on VMWare ESXi servers. |
| T1486 Data Encrypted for Impact |
GroupAkira | Akira encrypts files in victim environments as part of ransomware operations. |
| T1486 Data Encrypted for Impact |
GroupStorm-0501 | Storm-0501 has encrypted files in victim environments using ransomware as a service (RaaS) including Sabbath, Hive, BlackCat, Hunters International, LockBit 3.0 and Embargo ransomware. |
| T1486 Data Encrypted for Impact |
GroupTA505 | TA505 has used a wide variety of ransomware, such as Clop, Locky, Jaff, Bart, Philadelphia, and GlobeImposter, to encrypt victim files and demand a ransom payment. |
| T1486 Data Encrypted for Impact |
GroupMedusa Group | Medusa Group has encrypted files using AES-256 encryption which then appends the file extension “.medusa” to encrypted files and leaves a ransomware note named “!READ_ME_MEDUSA!!!.txt.” |
| T1486 Data Encrypted for Impact |
GroupWater Galura | Water Galura has encrypted files on victim networks through the generation of Qilin ransomware payloads. |
| T1486 Data Encrypted for Impact |
GroupINC Ransom | INC Ransom has used INC Ransomware to encrypt victim's data. |
| T1486 Data Encrypted for Impact |
GroupMoonstone Sleet | Moonstone Sleet has deployed ransomware in victim environments. |
| T1486 Data Encrypted for Impact |
GroupVOID MANTICORE | VOID MANTICORE has utilized legitimate disk encryption utilities to increase likelihood of encrypting system drives and reduce system recovery efforts. |
| T1486 Data Encrypted for Impact |
GroupMagic Hound | Magic Hound has used BitLocker and DiskCryptor to encrypt targeted workstations. |
| T1486 Data Encrypted for Impact |
GroupFIN8 | FIN8 has deployed ransomware such as Ragnar Locker, White Rabbit, and attempted to execute Noberus on compromised networks. |
| T1486 Data Encrypted for Impact |
MalwareEKANS | EKANS uses standard encryption library functions to encrypt files. |
| T1486 Data Encrypted for Impact |
MalwareSynAck | SynAck encrypts the victims machine followed by asking the victim to pay a ransom. |
| T1486 Data Encrypted for Impact |
MalwareAvosLocker | AvosLocker has encrypted files and network resources using AES-256 and added an `.avos`, `.avos2`, or `.AvosLinux` extension to filenames. |
| T1486 Data Encrypted for Impact |
MalwareRobbinHood | RobbinHood will search for an RSA encryption key and then perform its encryption process on the system files. |
| T1486 Data Encrypted for Impact |
MalwareRansomHub | RansomHub can use Elliptic Curve Encryption to encrypt files on targeted systems. RansomHub can also skip content at regular intervals (ex. encrypt 1 MB, skip 3 MB) to optomize performance and enable faster encryption for large files. |
| T1486 Data Encrypted for Impact |
MalwarePrestige | Prestige has leveraged the CryptoPP C++ library to encrypt files on target systems using AES and appended filenames with `.enc`. |
| T1486 Data Encrypted for Impact |
MalwarePlaycrypt | Playcrypt encrypts files on targeted hosts with an AES-RSA hybrid encryption, encrypting every other file portion of 0x100000 bytes. |
| T1486 Data Encrypted for Impact |
MalwareMedusa Ransomware | Medusa Ransomware has encrypted files using AES-256 encryption, which then appends the file extension “.medusa” to encrypted files and leaves a ransomware note named “!READ_ME_MEDUSA!!!.txt.” |
| T1486 Data Encrypted for Impact |
MalwareBad Rabbit | Bad Rabbit has encrypted files and disks using AES-128-CBC and RSA-2048. |
| T1486 Data Encrypted for Impact |
MalwareShrinkLocker | ShrinkLocker uses the legitimate BitLocker application to encrypt victim files for ransom. |
| T1486 Data Encrypted for Impact |
MalwareBlackByte 2.0 Ransomware | BlackByte 2.0 Ransomware is a ransomware variant associated with BlackByte operations. |
| T1486 Data Encrypted for Impact |
MalwareWastedLocker | WastedLocker can encrypt data and leave a ransom note. |
| T1486 Data Encrypted for Impact |
MalwareProLock | ProLock can encrypt files on a compromised host with RC6, and encrypts the key with RSA-1024. |
| T1486 Data Encrypted for Impact |
MalwareMoneybird | Moneybird targets a common set of file types such as documents, certificates, and database files for encryption while avoiding executable, dynamic linked libraries, and similar items. |
| T1486 Data Encrypted for Impact |
MalwareApostle | Apostle creates new, encrypted versions of files then deletes the originals, with the new filenames consisting of a random GUID and ".lock" for an extension. |
| T1486 Data Encrypted for Impact |
MalwareSamSam | SamSam encrypts victim files using RSA-2048 encryption and demands a ransom be paid in Bitcoin to decrypt those files. |
| T1486 Data Encrypted for Impact |
MalwareConti | Conti can use |
| T1486 Data Encrypted for Impact |
MalwareMegazord | Megazord can encrypt files on targeted Windows hosts leaving them with a ".powerranges" file extension. |
| T1486 Data Encrypted for Impact |
MalwareDiavol | Diavol has encrypted files using an RSA key though the `CryptEncrypt` API and has appended filenames with ".lock64". |
| T1486 Data Encrypted for Impact |
MalwareBlackCat | BlackCat has the ability to encrypt Windows devices, Linux devices, and VMWare instances. |
| T1486 Data Encrypted for Impact |
MalwareRagnar Locker | Ragnar Locker encrypts files on the local machine and mapped drives prior to displaying a note demanding a ransom. |
| T1486 Data Encrypted for Impact |
MalwareDCSrv | DCSrv has encrypted drives using the core encryption mechanism from DiskCryptor. |
| T1486 Data Encrypted for Impact |
MalwareNotPetya | NotPetya encrypts user files and disk structures like the MBR with 2048-bit RSA. |
| T1486 Data Encrypted for Impact |
MalwareAvaddon | Avaddon encrypts the victim system using a combination of AES256 and RSA encryption schemes. |
| T1486 Data Encrypted for Impact |
MalwareLockerGoga | LockerGoga has encrypted files, including core Windows OS files, using RSA-OAEP MGF1 and then demanded Bitcoin be paid for the decryption key. |
| T1486 Data Encrypted for Impact |
MalwareHELLOKITTY | HELLOKITTY can use an embedded RSA-2048 public key to encrypt victim data for ransom. |
| T1486 Data Encrypted for Impact |
MalwareCheerscrypt | Cheerscrypt can encrypt data on victim machines using a Sosemanuk stream cipher with an Elliptic-curve Diffie–Hellman (ECDH) generated key. |
| T1486 Data Encrypted for Impact |
MalwareBabuk | Babuk can use ChaCha8 and ECDH to encrypt data. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.