Real-world descriptions of how a group, tool or campaign used a technique.
62 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1486 Data Encrypted for Impact |
MalwareEKANS | EKANS uses standard encryption library functions to encrypt files. |
| T1486 Data Encrypted for Impact |
MalwareSynAck | SynAck encrypts the victims machine followed by asking the victim to pay a ransom. |
| T1486 Data Encrypted for Impact |
MalwareAvosLocker | AvosLocker has encrypted files and network resources using AES-256 and added an `.avos`, `.avos2`, or `.AvosLinux` extension to filenames. |
| T1486 Data Encrypted for Impact |
MalwareRobbinHood | RobbinHood will search for an RSA encryption key and then perform its encryption process on the system files. |
| T1486 Data Encrypted for Impact |
MalwareRansomHub | RansomHub can use Elliptic Curve Encryption to encrypt files on targeted systems. RansomHub can also skip content at regular intervals (ex. encrypt 1 MB, skip 3 MB) to optomize performance and enable faster encryption for large files. |
| T1486 Data Encrypted for Impact |
MalwarePrestige | Prestige has leveraged the CryptoPP C++ library to encrypt files on target systems using AES and appended filenames with `.enc`. |
| T1486 Data Encrypted for Impact |
MalwarePlaycrypt | Playcrypt encrypts files on targeted hosts with an AES-RSA hybrid encryption, encrypting every other file portion of 0x100000 bytes. |
| T1486 Data Encrypted for Impact |
MalwareMedusa Ransomware | Medusa Ransomware has encrypted files using AES-256 encryption, which then appends the file extension “.medusa” to encrypted files and leaves a ransomware note named “!READ_ME_MEDUSA!!!.txt.” |
| T1486 Data Encrypted for Impact |
MalwareBad Rabbit | Bad Rabbit has encrypted files and disks using AES-128-CBC and RSA-2048. |
| T1486 Data Encrypted for Impact |
MalwareShrinkLocker | ShrinkLocker uses the legitimate BitLocker application to encrypt victim files for ransom. |
| T1486 Data Encrypted for Impact |
MalwareBlackByte 2.0 Ransomware | BlackByte 2.0 Ransomware is a ransomware variant associated with BlackByte operations. |
| T1486 Data Encrypted for Impact |
MalwareWastedLocker | WastedLocker can encrypt data and leave a ransom note. |
| T1486 Data Encrypted for Impact |
MalwareProLock | ProLock can encrypt files on a compromised host with RC6, and encrypts the key with RSA-1024. |
| T1486 Data Encrypted for Impact |
MalwareMoneybird | Moneybird targets a common set of file types such as documents, certificates, and database files for encryption while avoiding executable, dynamic linked libraries, and similar items. |
| T1486 Data Encrypted for Impact |
MalwareApostle | Apostle creates new, encrypted versions of files then deletes the originals, with the new filenames consisting of a random GUID and ".lock" for an extension. |
| T1486 Data Encrypted for Impact |
MalwareSamSam | SamSam encrypts victim files using RSA-2048 encryption and demands a ransom be paid in Bitcoin to decrypt those files. |
| T1486 Data Encrypted for Impact |
MalwareConti | Conti can use |
| T1486 Data Encrypted for Impact |
MalwareMegazord | Megazord can encrypt files on targeted Windows hosts leaving them with a ".powerranges" file extension. |
| T1486 Data Encrypted for Impact |
MalwareDiavol | Diavol has encrypted files using an RSA key though the `CryptEncrypt` API and has appended filenames with ".lock64". |
| T1486 Data Encrypted for Impact |
MalwareBlackCat | BlackCat has the ability to encrypt Windows devices, Linux devices, and VMWare instances. |
| T1486 Data Encrypted for Impact |
MalwareRagnar Locker | Ragnar Locker encrypts files on the local machine and mapped drives prior to displaying a note demanding a ransom. |
| T1486 Data Encrypted for Impact |
MalwareDCSrv | DCSrv has encrypted drives using the core encryption mechanism from DiskCryptor. |
| T1486 Data Encrypted for Impact |
MalwareNotPetya | NotPetya encrypts user files and disk structures like the MBR with 2048-bit RSA. |
| T1486 Data Encrypted for Impact |
MalwareAvaddon | Avaddon encrypts the victim system using a combination of AES256 and RSA encryption schemes. |
| T1486 Data Encrypted for Impact |
MalwareLockerGoga | LockerGoga has encrypted files, including core Windows OS files, using RSA-OAEP MGF1 and then demanded Bitcoin be paid for the decryption key. |
| T1486 Data Encrypted for Impact |
MalwareHELLOKITTY | HELLOKITTY can use an embedded RSA-2048 public key to encrypt victim data for ransom. |
| T1486 Data Encrypted for Impact |
MalwareCheerscrypt | Cheerscrypt can encrypt data on victim machines using a Sosemanuk stream cipher with an Elliptic-curve Diffie–Hellman (ECDH) generated key. |
| T1486 Data Encrypted for Impact |
MalwareBabuk | Babuk can use ChaCha8 and ECDH to encrypt data. |
| T1486 Data Encrypted for Impact |
MalwareXbash | Xbash has maliciously encrypted victim's database systems and demanded a cryptocurrency ransom be paid. |
| T1486 Data Encrypted for Impact |
MalwareCuba | Cuba has the ability to encrypt system data and add the ".cuba" extension to encrypted files. |
| T1486 Data Encrypted for Impact |
MalwareDEATHRANSOM | DEATHRANSOM can use public and private key pair encryption to encrypt files for ransom payment. |
| T1486 Data Encrypted for Impact |
MalwareAkira | Akira can encrypt victim filesystems for financial extortion purposes including through the use of the ChaCha20 and ChaCha8 stream ciphers. |
| T1486 Data Encrypted for Impact |
MalwareDarkGate | DarkGate can deploy follow-on ransomware payloads. |
| T1486 Data Encrypted for Impact |
MalwareLockBit 3.0 | LockBit 3.0 can encrypt targeted data using the AES-256, ChaCha20, or RSA-2048 algorithms. |
| T1486 Data Encrypted for Impact |
MalwareThiefQuest | ThiefQuest encrypts a set of file extensions on a host, deletes the original files, and provides a ransom note with no contact information. |
| T1486 Data Encrypted for Impact |
MalwareNetwalker | Netwalker can encrypt files on infected machines to extort victims. |
| T1486 Data Encrypted for Impact |
MalwareWannaCry | WannaCry encrypts user files and demands that a ransom be paid in Bitcoin to decrypt those files. |
| T1486 Data Encrypted for Impact |
MalwarePay2Key | Pay2Key can encrypt data on victim's machines using RSA and AES algorithms in order to extort a ransom payment for decryption. |
| T1486 Data Encrypted for Impact |
MalwareLODEINFO | LODEINFO can incorporate a ransom command to encrypt specified files and folders. |
| T1486 Data Encrypted for Impact |
MalwareRoyal | Royal uses a multi-threaded encryption process that can partially encrypt targeted files with the OpenSSL library and the AES256 algorithm. |
| T1486 Data Encrypted for Impact |
MalwareEmbargo | Embargo has the ability to encrypt files with the ChaCha20 and Curve25519 cryptographic algorithms. Embargo also has the ability to encrypt system data and add a random six-letter extension consisting of hexadecimal characters such as ".b58eeb" or “.3d828a” to encrypted files. |
| T1486 Data Encrypted for Impact |
MalwareShamoon | Shamoon has an operational mode for encrypting data instead of overwriting it. |
| T1486 Data Encrypted for Impact |
MalwareBlack Basta | Black Basta can encrypt files with the ChaCha20 cypher and using a multithreaded process to increase speed. Black Basta has also encrypted files while the victim system is in safe mode, appending `.basta` upon completion. BlackBerry Black Basta May 2022Check Point Black Basta October 2022Cyble Black Basta May 2022Deep Instinct Black Basta August 2022Minerva Labs Black Basta May 2022NCC Group Black Basta June 2022Palo Alto Networks Black Basta August 2022Trend Micro Black Basta May 2022Trend Micro Black Basta Spotlight September 2022Uptycs Black Basta ESXi June 2022 |
| T1486 Data Encrypted for Impact |
MalwareMegaCortex | MegaCortex has used the open-source library, Mbed Crypto, and generated AES keys to carry out the file encryption process. |
| T1486 Data Encrypted for Impact |
MalwareAkira _v2 | The Akira _v2 encryptor targets the `/vmfs/volumes/` path by default and can use the rust-crypto 0.2.36 library crate for the encryption processes. |
| T1486 Data Encrypted for Impact |
MalwareBlackByte Ransomware | BlackByte Ransomware is ransomware using a shared key across victims for encryption. |
| T1486 Data Encrypted for Impact |
MalwareRyuk | Ryuk has used a combination of symmetric (AES) and asymmetric (RSA) encryption to encrypt files. Files have been encrypted with their own AES key and given a file extension of .RYK. Encrypted directories have had a ransom note of RyukReadMe.txt written to the directory. |
| T1486 Data Encrypted for Impact |
MalwarePysa | Pysa has used RSA and AES-CBC encryption algorithm to encrypt a list of targeted file extensions. |
| T1486 Data Encrypted for Impact |
MalwareLockBit 2.0 | LockBit 2.0 can use standard AES and elliptic-curve cryptography algorithms to encrypt victim data. |
| T1486 Data Encrypted for Impact |
MalwareJCry | JCry has encrypted files and demanded Bitcoin to decrypt those files. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.