Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1486 Data Encrypted for Impact |
MalwareXbash | Xbash has maliciously encrypted victim's database systems and demanded a cryptocurrency ransom be paid. |
| T1486 Data Encrypted for Impact |
MalwareCuba | Cuba has the ability to encrypt system data and add the ".cuba" extension to encrypted files. |
| T1486 Data Encrypted for Impact |
MalwareDEATHRANSOM | DEATHRANSOM can use public and private key pair encryption to encrypt files for ransom payment. |
| T1486 Data Encrypted for Impact |
MalwareAkira | Akira can encrypt victim filesystems for financial extortion purposes including through the use of the ChaCha20 and ChaCha8 stream ciphers. |
| T1486 Data Encrypted for Impact |
MalwareDarkGate | DarkGate can deploy follow-on ransomware payloads. |
| T1486 Data Encrypted for Impact |
MalwareLockBit 3.0 | LockBit 3.0 can encrypt targeted data using the AES-256, ChaCha20, or RSA-2048 algorithms. |
| T1486 Data Encrypted for Impact |
MalwareThiefQuest | ThiefQuest encrypts a set of file extensions on a host, deletes the original files, and provides a ransom note with no contact information. |
| T1486 Data Encrypted for Impact |
MalwareNetwalker | Netwalker can encrypt files on infected machines to extort victims. |
| T1486 Data Encrypted for Impact |
MalwareWannaCry | WannaCry encrypts user files and demands that a ransom be paid in Bitcoin to decrypt those files. |
| T1486 Data Encrypted for Impact |
MalwarePay2Key | Pay2Key can encrypt data on victim's machines using RSA and AES algorithms in order to extort a ransom payment for decryption. |
| T1486 Data Encrypted for Impact |
MalwareLODEINFO | LODEINFO can incorporate a ransom command to encrypt specified files and folders. |
| T1486 Data Encrypted for Impact |
MalwareRoyal | Royal uses a multi-threaded encryption process that can partially encrypt targeted files with the OpenSSL library and the AES256 algorithm. |
| T1486 Data Encrypted for Impact |
MalwareEmbargo | Embargo has the ability to encrypt files with the ChaCha20 and Curve25519 cryptographic algorithms. Embargo also has the ability to encrypt system data and add a random six-letter extension consisting of hexadecimal characters such as ".b58eeb" or “.3d828a” to encrypted files. |
| T1486 Data Encrypted for Impact |
MalwareShamoon | Shamoon has an operational mode for encrypting data instead of overwriting it. |
| T1486 Data Encrypted for Impact |
MalwareBlack Basta | Black Basta can encrypt files with the ChaCha20 cypher and using a multithreaded process to increase speed. Black Basta has also encrypted files while the victim system is in safe mode, appending `.basta` upon completion. BlackBerry Black Basta May 2022Check Point Black Basta October 2022Cyble Black Basta May 2022Deep Instinct Black Basta August 2022Minerva Labs Black Basta May 2022NCC Group Black Basta June 2022Palo Alto Networks Black Basta August 2022Trend Micro Black Basta May 2022Trend Micro Black Basta Spotlight September 2022Uptycs Black Basta ESXi June 2022 |
| T1486 Data Encrypted for Impact |
MalwareMegaCortex | MegaCortex has used the open-source library, Mbed Crypto, and generated AES keys to carry out the file encryption process. |
| T1486 Data Encrypted for Impact |
MalwareAkira _v2 | The Akira _v2 encryptor targets the `/vmfs/volumes/` path by default and can use the rust-crypto 0.2.36 library crate for the encryption processes. |
| T1486 Data Encrypted for Impact |
MalwareBlackByte Ransomware | BlackByte Ransomware is ransomware using a shared key across victims for encryption. |
| T1486 Data Encrypted for Impact |
MalwareRyuk | Ryuk has used a combination of symmetric (AES) and asymmetric (RSA) encryption to encrypt files. Files have been encrypted with their own AES key and given a file extension of .RYK. Encrypted directories have had a ransom note of RyukReadMe.txt written to the directory. |
| T1486 Data Encrypted for Impact |
MalwarePysa | Pysa has used RSA and AES-CBC encryption algorithm to encrypt a list of targeted file extensions. |
| T1486 Data Encrypted for Impact |
MalwareLockBit 2.0 | LockBit 2.0 can use standard AES and elliptic-curve cryptography algorithms to encrypt victim data. |
| T1486 Data Encrypted for Impact |
MalwareJCry | JCry has encrypted files and demanded Bitcoin to decrypt those files. |
| T1486 Data Encrypted for Impact |
MalwareREvil | REvil can encrypt files on victim systems and demands a ransom to decrypt the files. |
| T1486 Data Encrypted for Impact |
MalwareROADSWEEP | ROADSWEEP can RC4 encrypt content in blocks on targeted systems. |
| T1486 Data Encrypted for Impact |
MalwareClop | Clop can encrypt files using AES, RSA, and RC4 and will add the ".clop" extension to encrypted files. |
| T1486 Data Encrypted for Impact |
MalwareEgregor | Egregor can encrypt all non-system files using a hybrid AES-RSA algorithm prior to displaying a ransom note. |
| T1486 Data Encrypted for Impact |
MalwareMaze | Maze has disrupted systems by encrypting files on targeted machines, claiming to decrypt files if a ransom payment is made. Maze has used the ChaCha algorithm, based on Salsa20, and an RSA algorithm to encrypt files. |
| T1486 Data Encrypted for Impact |
MalwareXCSSET | XCSSET performs AES-CBC encryption on files under |
| T1486 Data Encrypted for Impact |
MalwareKillDisk | KillDisk has a ransomware component that encrypts files with an AES key that is also RSA-1028 encrypted. |
| T1486 Data Encrypted for Impact |
MalwareQilin | Qilin can use AES-256 or ChaCha20 for domain-wide encryption of victim servers and workstations and RSA-4096 or RSA-2048 to secure generated encryption keys. |
| T1486 Data Encrypted for Impact |
MalwareINC Ransomware | INC Ransomware can encrypt data on victim systems, including through the use of partial encryption and multi-threading to speed encryption. |
| T1486 Data Encrypted for Impact |
MalwareFIVEHANDS | FIVEHANDS can use an embedded NTRU public key to encrypt data for ransom. |
| T1486 Data Encrypted for Impact |
MalwareSeth-Locker | Seth-Locker can encrypt files on a targeted system, appending them with the suffix .seth. |
| T1486 Data Encrypted for Impact |
MalwareBitPaymer | BitPaymer can import a hard-coded RSA 1024-bit public key, generate a 128-bit RC4 key for each file, and encrypt the file in place, appending |
| T1486 Data Encrypted for Impact |
GroupTeamPCP | TeamPCP has deployed ransomware and has announced partnerships with ransomware groups including Vect and CipherForce in online criminal forums. |
| T1489 Service Stop |
GroupIndrik Spider | Indrik Spider has used PsExec to stop services prior to the execution of ransomware. |
| T1489 Service Stop |
GroupKimsuky | Kimsuky has disabled actively running virtual environments using the `KillMe` function to include VMware, Microsoft Hypervisors, and VirtualBox. |
| T1489 Service Stop |
GroupSandworm Team | Sandworm Team attempts to stop the MSSQL Windows service to ensure successful encryption of locked files. |
| T1489 Service Stop |
GroupMedusa Group | Medusa Group has terminated services related to backups, security, databases, communication, filesharing and websites. |
| T1489 Service Stop |
GroupLazarus Group | Lazarus Group has stopped the MSExchangeIS service to render Exchange contents inaccessible to users. |
| T1489 Service Stop |
GroupLAPSUS$ | LAPSUS$ has shut down virtual machines from within a victim's on-premise VMware ESXi infrastructure. |
| T1489 Service Stop |
GroupWizard Spider | Wizard Spider has used taskkill.exe and net.exe to stop backup, catalog, cloud, and other services prior to network encryption. |
| T1489 Service Stop |
MalwareEKANS | EKANS stops database, data backup solution, antivirus, and ICS-related processes. |
| T1489 Service Stop |
MalwareBRICKSTORM | BRICKSTORM has terminated an existing process to ensure that its own new process can execute. |
| T1489 Service Stop |
MalwareAvosLocker | AvosLocker has terminated specific processes before encryption. |
| T1489 Service Stop |
MalwareRobbinHood | RobbinHood stops 181 Windows services on the system before beginning the encryption process. |
| T1489 Service Stop |
MalwareRansomHub | RansomHub has the ability to terminate specified services. |
| T1489 Service Stop |
MalwarePrestige | Prestige has attempted to stop the MSSQL Windows service to ensure successful encryption using `C:\Windows\System32\net.exe stop MSSQLSERVER`. |
| T1489 Service Stop |
MalwareInvisibleFerret | InvisibleFerret has terminated Chrome and Brave browsers using the `taskkill` command on Windows and the `killall` command on other systems such as Linux and macOS. InvisibleFerret has also utilized it’s `ssh_kill` command to terminate Chrome and Brave browser processes. |
| T1489 Service Stop |
MalwareHannotog | Hannotog can stop Windows services. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.