ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1486
Data Encrypted for Impact
MalwareXbash

Xbash has maliciously encrypted victim's database systems and demanded a cryptocurrency ransom be paid.

T1486
Data Encrypted for Impact
MalwareCuba

Cuba has the ability to encrypt system data and add the ".cuba" extension to encrypted files.

T1486
Data Encrypted for Impact
MalwareDEATHRANSOM

DEATHRANSOM can use public and private key pair encryption to encrypt files for ransom payment.

T1486
Data Encrypted for Impact
MalwareAkira

Akira can encrypt victim filesystems for financial extortion purposes including through the use of the ChaCha20 and ChaCha8 stream ciphers.

T1486
Data Encrypted for Impact
MalwareDarkGate

DarkGate can deploy follow-on ransomware payloads.

T1486
Data Encrypted for Impact
MalwareLockBit 3.0

LockBit 3.0 can encrypt targeted data using the AES-256, ChaCha20, or RSA-2048 algorithms.

T1486
Data Encrypted for Impact
MalwareThiefQuest

ThiefQuest encrypts a set of file extensions on a host, deletes the original files, and provides a ransom note with no contact information.

T1486
Data Encrypted for Impact
MalwareNetwalker

Netwalker can encrypt files on infected machines to extort victims.

T1486
Data Encrypted for Impact
MalwareWannaCry

WannaCry encrypts user files and demands that a ransom be paid in Bitcoin to decrypt those files.

T1486
Data Encrypted for Impact
MalwarePay2Key

Pay2Key can encrypt data on victim's machines using RSA and AES algorithms in order to extort a ransom payment for decryption.

T1486
Data Encrypted for Impact
MalwareLODEINFO

LODEINFO can incorporate a ransom command to encrypt specified files and folders.

T1486
Data Encrypted for Impact
MalwareRoyal

Royal uses a multi-threaded encryption process that can partially encrypt targeted files with the OpenSSL library and the AES256 algorithm.

T1486
Data Encrypted for Impact
MalwareEmbargo

Embargo has the ability to encrypt files with the ChaCha20 and Curve25519 cryptographic algorithms. Embargo also has the ability to encrypt system data and add a random six-letter extension consisting of hexadecimal characters such as ".b58eeb" or “.3d828a” to encrypted files.

T1486
Data Encrypted for Impact
MalwareShamoon

Shamoon has an operational mode for encrypting data instead of overwriting it.

T1486
Data Encrypted for Impact
MalwareBlack Basta

Black Basta can encrypt files with the ChaCha20 cypher and using a multithreaded process to increase speed. Black Basta has also encrypted files while the victim system is in safe mode, appending `.basta` upon completion.

T1486
Data Encrypted for Impact
MalwareMegaCortex

MegaCortex has used the open-source library, Mbed Crypto, and generated AES keys to carry out the file encryption process.

T1486
Data Encrypted for Impact
MalwareAkira _v2

The Akira _v2 encryptor targets the `/vmfs/volumes/` path by default and can use the rust-crypto 0.2.36 library crate for the encryption processes.

T1486
Data Encrypted for Impact
MalwareBlackByte Ransomware

BlackByte Ransomware is ransomware using a shared key across victims for encryption.

T1486
Data Encrypted for Impact
MalwareRyuk

Ryuk has used a combination of symmetric (AES) and asymmetric (RSA) encryption to encrypt files. Files have been encrypted with their own AES key and given a file extension of .RYK. Encrypted directories have had a ransom note of RyukReadMe.txt written to the directory.

T1486
Data Encrypted for Impact
MalwarePysa

Pysa has used RSA and AES-CBC encryption algorithm to encrypt a list of targeted file extensions.

T1486
Data Encrypted for Impact
MalwareLockBit 2.0

LockBit 2.0 can use standard AES and elliptic-curve cryptography algorithms to encrypt victim data.

T1486
Data Encrypted for Impact
MalwareJCry

JCry has encrypted files and demanded Bitcoin to decrypt those files.

T1486
Data Encrypted for Impact
MalwareREvil

REvil can encrypt files on victim systems and demands a ransom to decrypt the files.

T1486
Data Encrypted for Impact
MalwareROADSWEEP

ROADSWEEP can RC4 encrypt content in blocks on targeted systems.

T1486
Data Encrypted for Impact
MalwareClop

Clop can encrypt files using AES, RSA, and RC4 and will add the ".clop" extension to encrypted files.

T1486
Data Encrypted for Impact
MalwareEgregor

Egregor can encrypt all non-system files using a hybrid AES-RSA algorithm prior to displaying a ransom note.

T1486
Data Encrypted for Impact
MalwareMaze

Maze has disrupted systems by encrypting files on targeted machines, claiming to decrypt files if a ransom payment is made. Maze has used the ChaCha algorithm, based on Salsa20, and an RSA algorithm to encrypt files.

T1486
Data Encrypted for Impact
MalwareXCSSET

XCSSET performs AES-CBC encryption on files under ~/Documents, ~/Downloads, and
~/Desktop with a fixed key and renames files to give them a .enc extension. Only files with sizes
less than 500MB are encrypted.

T1486
Data Encrypted for Impact
MalwareKillDisk

KillDisk has a ransomware component that encrypts files with an AES key that is also RSA-1028 encrypted.

T1486
Data Encrypted for Impact
MalwareQilin

Qilin can use AES-256 or ChaCha20 for domain-wide encryption of victim servers and workstations and RSA-4096 or RSA-2048 to secure generated encryption keys.

T1486
Data Encrypted for Impact
MalwareINC Ransomware

INC Ransomware can encrypt data on victim systems, including through the use of partial encryption and multi-threading to speed encryption.

T1486
Data Encrypted for Impact
MalwareFIVEHANDS

FIVEHANDS can use an embedded NTRU public key to encrypt data for ransom.

T1486
Data Encrypted for Impact
MalwareSeth-Locker

Seth-Locker can encrypt files on a targeted system, appending them with the suffix .seth.

T1486
Data Encrypted for Impact
MalwareBitPaymer

BitPaymer can import a hard-coded RSA 1024-bit public key, generate a 128-bit RC4 key for each file, and encrypt the file in place, appending .locked to the filename.

T1486
Data Encrypted for Impact
GroupTeamPCP

TeamPCP has deployed ransomware and has announced partnerships with ransomware groups including Vect and CipherForce in online criminal forums.

T1489
Service Stop
GroupIndrik Spider

Indrik Spider has used PsExec to stop services prior to the execution of ransomware.

T1489
Service Stop
GroupKimsuky

Kimsuky has disabled actively running virtual environments using the `KillMe` function to include VMware, Microsoft Hypervisors, and VirtualBox.

T1489
Service Stop
GroupSandworm Team

Sandworm Team attempts to stop the MSSQL Windows service to ensure successful encryption of locked files.

T1489
Service Stop
GroupMedusa Group

Medusa Group has terminated services related to backups, security, databases, communication, filesharing and websites.

T1489
Service Stop
GroupLazarus Group

Lazarus Group has stopped the MSExchangeIS service to render Exchange contents inaccessible to users.

T1489
Service Stop
GroupLAPSUS$

LAPSUS$ has shut down virtual machines from within a victim's on-premise VMware ESXi infrastructure.

T1489
Service Stop
GroupWizard Spider

Wizard Spider has used taskkill.exe and net.exe to stop backup, catalog, cloud, and other services prior to network encryption.

T1489
Service Stop
MalwareEKANS

EKANS stops database, data backup solution, antivirus, and ICS-related processes.

T1489
Service Stop
MalwareBRICKSTORM

BRICKSTORM has terminated an existing process to ensure that its own new process can execute.

T1489
Service Stop
MalwareAvosLocker

AvosLocker has terminated specific processes before encryption.

T1489
Service Stop
MalwareRobbinHood

RobbinHood stops 181 Windows services on the system before beginning the encryption process.

T1489
Service Stop
MalwareRansomHub

RansomHub has the ability to terminate specified services.

T1489
Service Stop
MalwarePrestige

Prestige has attempted to stop the MSSQL Windows service to ensure successful encryption using `C:\Windows\System32\net.exe stop MSSQLSERVER`.

T1489
Service Stop
MalwareInvisibleFerret

InvisibleFerret has terminated Chrome and Brave browsers using the `taskkill` command on Windows and the `killall` command on other systems such as Linux and macOS. InvisibleFerret has also utilized it’s `ssh_kill` command to terminate Chrome and Brave browser processes.

T1489
Service Stop
MalwareHannotog

Hannotog can stop Windows services.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.