ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1486×

62 examples

TechniqueUsed byProcedure example
T1486
Data Encrypted for Impact
MalwareEKANS

EKANS uses standard encryption library functions to encrypt files.

T1486
Data Encrypted for Impact
MalwareSynAck

SynAck encrypts the victims machine followed by asking the victim to pay a ransom.

T1486
Data Encrypted for Impact
MalwareAvosLocker

AvosLocker has encrypted files and network resources using AES-256 and added an `.avos`, `.avos2`, or `.AvosLinux` extension to filenames.

T1486
Data Encrypted for Impact
MalwareRobbinHood

RobbinHood will search for an RSA encryption key and then perform its encryption process on the system files.

T1486
Data Encrypted for Impact
MalwareRansomHub

RansomHub can use Elliptic Curve Encryption to encrypt files on targeted systems. RansomHub can also skip content at regular intervals (ex. encrypt 1 MB, skip 3 MB) to optomize performance and enable faster encryption for large files.

T1486
Data Encrypted for Impact
MalwarePrestige

Prestige has leveraged the CryptoPP C++ library to encrypt files on target systems using AES and appended filenames with `.enc`.

T1486
Data Encrypted for Impact
MalwarePlaycrypt

Playcrypt encrypts files on targeted hosts with an AES-RSA hybrid encryption, encrypting every other file portion of 0x100000 bytes.

T1486
Data Encrypted for Impact
MalwareMedusa Ransomware

Medusa Ransomware has encrypted files using AES-256 encryption, which then appends the file extension “.medusa” to encrypted files and leaves a ransomware note named “!READ_ME_MEDUSA!!!.txt.”

T1486
Data Encrypted for Impact
MalwareBad Rabbit

Bad Rabbit has encrypted files and disks using AES-128-CBC and RSA-2048.

T1486
Data Encrypted for Impact
MalwareShrinkLocker

ShrinkLocker uses the legitimate BitLocker application to encrypt victim files for ransom.

T1486
Data Encrypted for Impact
MalwareBlackByte 2.0 Ransomware

BlackByte 2.0 Ransomware is a ransomware variant associated with BlackByte operations.

T1486
Data Encrypted for Impact
MalwareWastedLocker

WastedLocker can encrypt data and leave a ransom note.

T1486
Data Encrypted for Impact
MalwareProLock

ProLock can encrypt files on a compromised host with RC6, and encrypts the key with RSA-1024.

T1486
Data Encrypted for Impact
MalwareMoneybird

Moneybird targets a common set of file types such as documents, certificates, and database files for encryption while avoiding executable, dynamic linked libraries, and similar items.

T1486
Data Encrypted for Impact
MalwareApostle

Apostle creates new, encrypted versions of files then deletes the originals, with the new filenames consisting of a random GUID and ".lock" for an extension.

T1486
Data Encrypted for Impact
MalwareSamSam

SamSam encrypts victim files using RSA-2048 encryption and demands a ransom be paid in Bitcoin to decrypt those files.

T1486
Data Encrypted for Impact
MalwareConti

Conti can use CreateIoCompletionPort(), PostQueuedCompletionStatus(), and GetQueuedCompletionPort() to rapidly encrypt files, excluding those with the extensions of .exe, .dll, and .lnk. It has used a different AES-256 encryption key per file with a bundled RAS-4096 public encryption key that is unique for each victim. Conti can use “Windows Restart Manager” to ensure files are unlocked and open for encryption.

T1486
Data Encrypted for Impact
MalwareMegazord

Megazord can encrypt files on targeted Windows hosts leaving them with a ".powerranges" file extension.

T1486
Data Encrypted for Impact
MalwareDiavol

Diavol has encrypted files using an RSA key though the `CryptEncrypt` API and has appended filenames with ".lock64".

T1486
Data Encrypted for Impact
MalwareBlackCat

BlackCat has the ability to encrypt Windows devices, Linux devices, and VMWare instances.

T1486
Data Encrypted for Impact
MalwareRagnar Locker

Ragnar Locker encrypts files on the local machine and mapped drives prior to displaying a note demanding a ransom.

T1486
Data Encrypted for Impact
MalwareDCSrv

DCSrv has encrypted drives using the core encryption mechanism from DiskCryptor.

T1486
Data Encrypted for Impact
MalwareNotPetya

NotPetya encrypts user files and disk structures like the MBR with 2048-bit RSA.

T1486
Data Encrypted for Impact
MalwareAvaddon

Avaddon encrypts the victim system using a combination of AES256 and RSA encryption schemes.

T1486
Data Encrypted for Impact
MalwareLockerGoga

LockerGoga has encrypted files, including core Windows OS files, using RSA-OAEP MGF1 and then demanded Bitcoin be paid for the decryption key.

T1486
Data Encrypted for Impact
MalwareHELLOKITTY

HELLOKITTY can use an embedded RSA-2048 public key to encrypt victim data for ransom.

T1486
Data Encrypted for Impact
MalwareCheerscrypt

Cheerscrypt can encrypt data on victim machines using a Sosemanuk stream cipher with an Elliptic-curve Diffie–Hellman (ECDH) generated key.

T1486
Data Encrypted for Impact
MalwareBabuk

Babuk can use ChaCha8 and ECDH to encrypt data.

T1486
Data Encrypted for Impact
MalwareXbash

Xbash has maliciously encrypted victim's database systems and demanded a cryptocurrency ransom be paid.

T1486
Data Encrypted for Impact
MalwareCuba

Cuba has the ability to encrypt system data and add the ".cuba" extension to encrypted files.

T1486
Data Encrypted for Impact
MalwareDEATHRANSOM

DEATHRANSOM can use public and private key pair encryption to encrypt files for ransom payment.

T1486
Data Encrypted for Impact
MalwareAkira

Akira can encrypt victim filesystems for financial extortion purposes including through the use of the ChaCha20 and ChaCha8 stream ciphers.

T1486
Data Encrypted for Impact
MalwareDarkGate

DarkGate can deploy follow-on ransomware payloads.

T1486
Data Encrypted for Impact
MalwareLockBit 3.0

LockBit 3.0 can encrypt targeted data using the AES-256, ChaCha20, or RSA-2048 algorithms.

T1486
Data Encrypted for Impact
MalwareThiefQuest

ThiefQuest encrypts a set of file extensions on a host, deletes the original files, and provides a ransom note with no contact information.

T1486
Data Encrypted for Impact
MalwareNetwalker

Netwalker can encrypt files on infected machines to extort victims.

T1486
Data Encrypted for Impact
MalwareWannaCry

WannaCry encrypts user files and demands that a ransom be paid in Bitcoin to decrypt those files.

T1486
Data Encrypted for Impact
MalwarePay2Key

Pay2Key can encrypt data on victim's machines using RSA and AES algorithms in order to extort a ransom payment for decryption.

T1486
Data Encrypted for Impact
MalwareLODEINFO

LODEINFO can incorporate a ransom command to encrypt specified files and folders.

T1486
Data Encrypted for Impact
MalwareRoyal

Royal uses a multi-threaded encryption process that can partially encrypt targeted files with the OpenSSL library and the AES256 algorithm.

T1486
Data Encrypted for Impact
MalwareEmbargo

Embargo has the ability to encrypt files with the ChaCha20 and Curve25519 cryptographic algorithms. Embargo also has the ability to encrypt system data and add a random six-letter extension consisting of hexadecimal characters such as ".b58eeb" or “.3d828a” to encrypted files.

T1486
Data Encrypted for Impact
MalwareShamoon

Shamoon has an operational mode for encrypting data instead of overwriting it.

T1486
Data Encrypted for Impact
MalwareBlack Basta

Black Basta can encrypt files with the ChaCha20 cypher and using a multithreaded process to increase speed. Black Basta has also encrypted files while the victim system is in safe mode, appending `.basta` upon completion.

T1486
Data Encrypted for Impact
MalwareMegaCortex

MegaCortex has used the open-source library, Mbed Crypto, and generated AES keys to carry out the file encryption process.

T1486
Data Encrypted for Impact
MalwareAkira _v2

The Akira _v2 encryptor targets the `/vmfs/volumes/` path by default and can use the rust-crypto 0.2.36 library crate for the encryption processes.

T1486
Data Encrypted for Impact
MalwareBlackByte Ransomware

BlackByte Ransomware is ransomware using a shared key across victims for encryption.

T1486
Data Encrypted for Impact
MalwareRyuk

Ryuk has used a combination of symmetric (AES) and asymmetric (RSA) encryption to encrypt files. Files have been encrypted with their own AES key and given a file extension of .RYK. Encrypted directories have had a ransom note of RyukReadMe.txt written to the directory.

T1486
Data Encrypted for Impact
MalwarePysa

Pysa has used RSA and AES-CBC encryption algorithm to encrypt a list of targeted file extensions.

T1486
Data Encrypted for Impact
MalwareLockBit 2.0

LockBit 2.0 can use standard AES and elliptic-curve cryptography algorithms to encrypt victim data.

T1486
Data Encrypted for Impact
MalwareJCry

JCry has encrypted files and demanded Bitcoin to decrypt those files.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.