Real-world descriptions of how a group, tool or campaign used a technique.
21 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwareShrinkLocker | ShrinkLocker captures the IP address of the victim system and sends this to the attacker following encryption. |
| T1041 Exfiltration Over C2 Channel |
MalwareShrinkLocker | ShrinkLocker will exfiltrate victim system information along with the encryption key via an HTTP POST. |
| T1047 Windows Management Instrumentation |
MalwareShrinkLocker | ShrinkLocker uses WMI to query information about the victim operating system. |
| T1057 Process Discovery |
MalwareShrinkLocker | ShrinkLocker checks whether the Bitlocker Drive Encryption Tools service is running. |
| T1059.001 PowerShell |
MalwareShrinkLocker | ShrinkLocker uses PowerShell to disable protectors used to secure the BitLocker encryption key on victim machines and then delete the key from the system. |
| T1059.005 Visual Basic |
MalwareShrinkLocker | ShrinkLocker is a VisualBasic script (VBS) object that calls multiple other operating system functions during execution. |
| T1070.004 File Deletion |
MalwareShrinkLocker | ShrinkLocker can delete itself depending on various checks performed during execution. |
| T1071.001 Web Protocols |
MalwareShrinkLocker | ShrinkLocker uses HTTP POST requests to communicate victim information back to the threat actor. |
| T1082 System Information Discovery |
MalwareShrinkLocker | ShrinkLocker uses WMI queries to gather various information about the victim machine and operating system. |
| T1102 Web Service |
MalwareShrinkLocker | ShrinkLocker uses a subdomain on the legitimate Cloudflare resource "trycloudflare[.]com" to obfuscate the threat actor's actual address and to tunnel information sent from victim systems. |
| T1112 Modify Registry |
MalwareShrinkLocker | ShrinkLocker modifies various registry keys associated with system logon and BitLocker functionality to effectively lock-out users following disk encryption. |
| T1124 System Time Discovery |
MalwareShrinkLocker | ShrinkLocker retrieves a system timestamp that is used in generating an encryption key. |
| T1480 Execution Guardrails |
MalwareShrinkLocker | ShrinkLocker will exit its "main" function if the victim domain name does not match provided criteria. |
| T1485 Data Destruction |
MalwareShrinkLocker | ShrinkLocker can initiate a destructive payload depending on the operating system check through resizing and reformatting portions of the victim machine's disk, leading to system instability and potential data corruption. |
| T1486 Data Encrypted for Impact |
MalwareShrinkLocker | ShrinkLocker uses the legitimate BitLocker application to encrypt victim files for ransom. |
| T1491.001 Internal Defacement |
MalwareShrinkLocker | ShrinkLocker renames disk labels on victim hosts to the threat actor's email address to enable the victim to contact the threat actor for ransom negotiation. |
| T1529 System Shutdown/Reboot |
MalwareShrinkLocker | ShrinkLocker can restart the victim system if it encounters an error during execution, and will forcibly shutdown the system following encryption to lock out victim users. |
| T1561.002 Disk Structure Wipe |
MalwareShrinkLocker | ShrinkLocker has used Diskpart to format newly-created partitions. |
| T1685 Disable or Modify Tools |
MalwareShrinkLocker | ShrinkLocker disables protectors used to secure the BitLocker encryption key on victim systems. |
| T1685.005 Clear Windows Event Logs |
MalwareShrinkLocker | ShrinkLocker calls Wevtutil to clear the Windows PowerShell and Microsoft-Windows-Powershell/Operational logs. |
| T1686 Disable or Modify System Firewall |
MalwareShrinkLocker | ShrinkLocker turns on the system firewall and deletes all of its rules during execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.