Real-world descriptions of how a group, tool or campaign used a technique.
22 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareRyuk | Ryuk has called |
| T1021.002 SMB/Windows Admin Shares |
MalwareRyuk | Ryuk has used the C$ network share for lateral movement. |
| T1027 Obfuscated Files or Information |
MalwareRyuk | Ryuk can use anti-disassembly and code transformation obfuscation techniques. |
| T1036 Masquerading |
MalwareRyuk | Ryuk can create .dll files that actually contain a Rich Text File format document. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareRyuk | Ryuk has constructed legitimate appearing installation folder paths by calling |
| T1053.005 Scheduled Task |
MalwareRyuk | Ryuk can remotely create a scheduled task to execute itself on a system. |
| T1055 Process Injection |
MalwareRyuk | Ryuk has injected itself into remote processes to encrypt files using a combination of |
| T1057 Process Discovery |
MalwareRyuk | Ryuk has called |
| T1059.003 Windows Command Shell |
MalwareRyuk | Ryuk has used |
| T1078.002 Domain Accounts |
MalwareRyuk | Ryuk can use stolen domain admin accounts to move laterally within a victim domain. |
| T1083 File and Directory Discovery |
MalwareRyuk | Ryuk has enumerated files and folders on all mounted drives. |
| T1106 Native API |
MalwareRyuk | Ryuk has used multiple native APIs including |
| T1134 Access Token Manipulation |
MalwareRyuk | Ryuk has attempted to adjust its token privileges to have the |
| T1205 Traffic Signaling |
MalwareRyuk | Ryuk has used Wake-on-Lan to power on turned off systems for lateral movement. |
| T1222.001 Windows Permissions |
MalwareRyuk | Ryuk can launch |
| T1486 Data Encrypted for Impact |
MalwareRyuk | Ryuk has used a combination of symmetric (AES) and asymmetric (RSA) encryption to encrypt files. Files have been encrypted with their own AES key and given a file extension of .RYK. Encrypted directories have had a ransom note of RyukReadMe.txt written to the directory. |
| T1489 Service Stop |
MalwareRyuk | Ryuk has called |
| T1490 Inhibit System Recovery |
MalwareRyuk | Ryuk has used |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareRyuk | Ryuk has used the Windows command line to create a Registry entry under |
| T1614.001 System Language Discovery |
MalwareRyuk | Ryuk has been observed to query the registry key |
| T1680 Local Storage Discovery |
MalwareRyuk | Ryuk has called |
| T1685 Disable or Modify Tools |
MalwareRyuk | Ryuk has stopped services related to anti-virus. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.