ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1486
Data Encrypted for Impact
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors deployed ransomware including 4L4MD4R and Warlock.

T1486
Data Encrypted for Impact
CampaignC0018

During C0018, the threat actors used AvosLocker ransomware to encrypt files on the compromised network.

T1486
Data Encrypted for Impact
CampaignC0015

During C0015, the threat actors used Conti ransomware to encrypt a compromised network.

T1486
Data Encrypted for Impact
CampaignHomeLand Justice

During HomeLand Justice, threat actors used ROADSWEEP ransomware to encrypt files on targeted systems.

T1486
Data Encrypted for Impact
GroupAPT38

APT38 has used Hermes ransomware to encrypt files with AES256.

T1486
Data Encrypted for Impact
GroupIndrik Spider

Indrik Spider has encrypted domain-controlled systems using BitPaymer. Additionally, Indrik Spider used PsExec to execute a ransomware script.

T1486
Data Encrypted for Impact
GroupBlackByte

BlackByte has encrypted victim files for ransom. Early versions of BlackByte ransomware used a common key for encryption, but later versions use unique keys per victim.

T1486
Data Encrypted for Impact
GroupAPT41

APT41 used a ransomware called Encryptor RaaS to encrypt files on the targeted systems and provide a ransom note to the user. APT41 also used Microsoft Bitlocker to encrypt workstations and Jetico’s BestCrypt to encrypt servers.

T1486
Data Encrypted for Impact
GroupStorm-1811

Storm-1811 is a financially-motivated entity linked to the deployment of Black Basta ransomware in victim environments.

T1486
Data Encrypted for Impact
GroupFIN7

FIN7 has encrypted virtual disk volumes on ESXi servers using a version of Darkside ransomware. Additionally, FIN7 has deployed ransomware as the end payload during big game hunting.

T1486
Data Encrypted for Impact
GroupSandworm Team

Sandworm Team has used Prestige ransomware to encrypt data at targeted organizations in transportation and related logistics industries in Ukraine and Poland.

T1486
Data Encrypted for Impact
GroupScattered Spider

Scattered Spider has used BlackCat and DragonForce ransomware to encrypt files including on VMWare ESXi servers.

T1486
Data Encrypted for Impact
GroupAkira

Akira encrypts files in victim environments as part of ransomware operations.

T1486
Data Encrypted for Impact
GroupStorm-0501

Storm-0501 has encrypted files in victim environments using ransomware as a service (RaaS) including Sabbath, Hive, BlackCat, Hunters International, LockBit 3.0 and Embargo ransomware.

T1486
Data Encrypted for Impact
GroupTA505

TA505 has used a wide variety of ransomware, such as Clop, Locky, Jaff, Bart, Philadelphia, and GlobeImposter, to encrypt victim files and demand a ransom payment.

T1486
Data Encrypted for Impact
GroupMedusa Group

Medusa Group has encrypted files using AES-256 encryption which then appends the file extension “.medusa” to encrypted files and leaves a ransomware note named “!READ_ME_MEDUSA!!!.txt.”

T1486
Data Encrypted for Impact
GroupWater Galura

Water Galura has encrypted files on victim networks through the generation of Qilin ransomware payloads.

T1486
Data Encrypted for Impact
GroupINC Ransom

INC Ransom has used INC Ransomware to encrypt victim's data.

T1486
Data Encrypted for Impact
GroupMoonstone Sleet

Moonstone Sleet has deployed ransomware in victim environments.

T1486
Data Encrypted for Impact
GroupVOID MANTICORE

VOID MANTICORE has utilized legitimate disk encryption utilities to increase likelihood of encrypting system drives and reduce system recovery efforts.

T1486
Data Encrypted for Impact
GroupMagic Hound

Magic Hound has used BitLocker and DiskCryptor to encrypt targeted workstations.

T1486
Data Encrypted for Impact
GroupFIN8

FIN8 has deployed ransomware such as Ragnar Locker, White Rabbit, and attempted to execute Noberus on compromised networks.

T1486
Data Encrypted for Impact
MalwareEKANS

EKANS uses standard encryption library functions to encrypt files.

T1486
Data Encrypted for Impact
MalwareSynAck

SynAck encrypts the victims machine followed by asking the victim to pay a ransom.

T1486
Data Encrypted for Impact
MalwareAvosLocker

AvosLocker has encrypted files and network resources using AES-256 and added an `.avos`, `.avos2`, or `.AvosLinux` extension to filenames.

T1486
Data Encrypted for Impact
MalwareRobbinHood

RobbinHood will search for an RSA encryption key and then perform its encryption process on the system files.

T1486
Data Encrypted for Impact
MalwareRansomHub

RansomHub can use Elliptic Curve Encryption to encrypt files on targeted systems. RansomHub can also skip content at regular intervals (ex. encrypt 1 MB, skip 3 MB) to optomize performance and enable faster encryption for large files.

T1486
Data Encrypted for Impact
MalwarePrestige

Prestige has leveraged the CryptoPP C++ library to encrypt files on target systems using AES and appended filenames with `.enc`.

T1486
Data Encrypted for Impact
MalwarePlaycrypt

Playcrypt encrypts files on targeted hosts with an AES-RSA hybrid encryption, encrypting every other file portion of 0x100000 bytes.

T1486
Data Encrypted for Impact
MalwareMedusa Ransomware

Medusa Ransomware has encrypted files using AES-256 encryption, which then appends the file extension “.medusa” to encrypted files and leaves a ransomware note named “!READ_ME_MEDUSA!!!.txt.”

T1486
Data Encrypted for Impact
MalwareBad Rabbit

Bad Rabbit has encrypted files and disks using AES-128-CBC and RSA-2048.

T1486
Data Encrypted for Impact
MalwareShrinkLocker

ShrinkLocker uses the legitimate BitLocker application to encrypt victim files for ransom.

T1486
Data Encrypted for Impact
MalwareBlackByte 2.0 Ransomware

BlackByte 2.0 Ransomware is a ransomware variant associated with BlackByte operations.

T1486
Data Encrypted for Impact
MalwareWastedLocker

WastedLocker can encrypt data and leave a ransom note.

T1486
Data Encrypted for Impact
MalwareProLock

ProLock can encrypt files on a compromised host with RC6, and encrypts the key with RSA-1024.

T1486
Data Encrypted for Impact
MalwareMoneybird

Moneybird targets a common set of file types such as documents, certificates, and database files for encryption while avoiding executable, dynamic linked libraries, and similar items.

T1486
Data Encrypted for Impact
MalwareApostle

Apostle creates new, encrypted versions of files then deletes the originals, with the new filenames consisting of a random GUID and ".lock" for an extension.

T1486
Data Encrypted for Impact
MalwareSamSam

SamSam encrypts victim files using RSA-2048 encryption and demands a ransom be paid in Bitcoin to decrypt those files.

T1486
Data Encrypted for Impact
MalwareConti

Conti can use CreateIoCompletionPort(), PostQueuedCompletionStatus(), and GetQueuedCompletionPort() to rapidly encrypt files, excluding those with the extensions of .exe, .dll, and .lnk. It has used a different AES-256 encryption key per file with a bundled RAS-4096 public encryption key that is unique for each victim. Conti can use “Windows Restart Manager” to ensure files are unlocked and open for encryption.

T1486
Data Encrypted for Impact
MalwareMegazord

Megazord can encrypt files on targeted Windows hosts leaving them with a ".powerranges" file extension.

T1486
Data Encrypted for Impact
MalwareDiavol

Diavol has encrypted files using an RSA key though the `CryptEncrypt` API and has appended filenames with ".lock64".

T1486
Data Encrypted for Impact
MalwareBlackCat

BlackCat has the ability to encrypt Windows devices, Linux devices, and VMWare instances.

T1486
Data Encrypted for Impact
MalwareRagnar Locker

Ragnar Locker encrypts files on the local machine and mapped drives prior to displaying a note demanding a ransom.

T1486
Data Encrypted for Impact
MalwareDCSrv

DCSrv has encrypted drives using the core encryption mechanism from DiskCryptor.

T1486
Data Encrypted for Impact
MalwareNotPetya

NotPetya encrypts user files and disk structures like the MBR with 2048-bit RSA.

T1486
Data Encrypted for Impact
MalwareAvaddon

Avaddon encrypts the victim system using a combination of AES256 and RSA encryption schemes.

T1486
Data Encrypted for Impact
MalwareLockerGoga

LockerGoga has encrypted files, including core Windows OS files, using RSA-OAEP MGF1 and then demanded Bitcoin be paid for the decryption key.

T1486
Data Encrypted for Impact
MalwareHELLOKITTY

HELLOKITTY can use an embedded RSA-2048 public key to encrypt victim data for ransom.

T1486
Data Encrypted for Impact
MalwareCheerscrypt

Cheerscrypt can encrypt data on victim machines using a Sosemanuk stream cipher with an Elliptic-curve Diffie–Hellman (ECDH) generated key.

T1486
Data Encrypted for Impact
MalwareBabuk

Babuk can use ChaCha8 and ECDH to encrypt data.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.