ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1486×

19 examples

TechniqueUsed byProcedure example
T1486
Data Encrypted for Impact
GroupAPT38

APT38 has used Hermes ransomware to encrypt files with AES256.

T1486
Data Encrypted for Impact
GroupIndrik Spider

Indrik Spider has encrypted domain-controlled systems using BitPaymer. Additionally, Indrik Spider used PsExec to execute a ransomware script.

T1486
Data Encrypted for Impact
GroupBlackByte

BlackByte has encrypted victim files for ransom. Early versions of BlackByte ransomware used a common key for encryption, but later versions use unique keys per victim.

T1486
Data Encrypted for Impact
GroupAPT41

APT41 used a ransomware called Encryptor RaaS to encrypt files on the targeted systems and provide a ransom note to the user. APT41 also used Microsoft Bitlocker to encrypt workstations and Jetico’s BestCrypt to encrypt servers.

T1486
Data Encrypted for Impact
GroupStorm-1811

Storm-1811 is a financially-motivated entity linked to the deployment of Black Basta ransomware in victim environments.

T1486
Data Encrypted for Impact
GroupFIN7

FIN7 has encrypted virtual disk volumes on ESXi servers using a version of Darkside ransomware. Additionally, FIN7 has deployed ransomware as the end payload during big game hunting.

T1486
Data Encrypted for Impact
GroupSandworm Team

Sandworm Team has used Prestige ransomware to encrypt data at targeted organizations in transportation and related logistics industries in Ukraine and Poland.

T1486
Data Encrypted for Impact
GroupScattered Spider

Scattered Spider has used BlackCat and DragonForce ransomware to encrypt files including on VMWare ESXi servers.

T1486
Data Encrypted for Impact
GroupAkira

Akira encrypts files in victim environments as part of ransomware operations.

T1486
Data Encrypted for Impact
GroupStorm-0501

Storm-0501 has encrypted files in victim environments using ransomware as a service (RaaS) including Sabbath, Hive, BlackCat, Hunters International, LockBit 3.0 and Embargo ransomware.

T1486
Data Encrypted for Impact
GroupTA505

TA505 has used a wide variety of ransomware, such as Clop, Locky, Jaff, Bart, Philadelphia, and GlobeImposter, to encrypt victim files and demand a ransom payment.

T1486
Data Encrypted for Impact
GroupMedusa Group

Medusa Group has encrypted files using AES-256 encryption which then appends the file extension “.medusa” to encrypted files and leaves a ransomware note named “!READ_ME_MEDUSA!!!.txt.”

T1486
Data Encrypted for Impact
GroupWater Galura

Water Galura has encrypted files on victim networks through the generation of Qilin ransomware payloads.

T1486
Data Encrypted for Impact
GroupINC Ransom

INC Ransom has used INC Ransomware to encrypt victim's data.

T1486
Data Encrypted for Impact
GroupMoonstone Sleet

Moonstone Sleet has deployed ransomware in victim environments.

T1486
Data Encrypted for Impact
GroupVOID MANTICORE

VOID MANTICORE has utilized legitimate disk encryption utilities to increase likelihood of encrypting system drives and reduce system recovery efforts.

T1486
Data Encrypted for Impact
GroupMagic Hound

Magic Hound has used BitLocker and DiskCryptor to encrypt targeted workstations.

T1486
Data Encrypted for Impact
GroupFIN8

FIN8 has deployed ransomware such as Ragnar Locker, White Rabbit, and attempted to execute Noberus on compromised networks.

T1486
Data Encrypted for Impact
GroupTeamPCP

TeamPCP has deployed ransomware and has announced partnerships with ransomware groups including Vect and CipherForce in online criminal forums.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.