CarbonBlack Threat Analysis Unit. (2019, March 22). TAU Threat Intelligence Notification – LockerGoga Ransomware. Retrieved April 16, 2019.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1070.004 File Deletion |
MalwareLockerGoga | LockerGoga has been observed deleting its original launcher after execution. |
| T1486 Data Encrypted for Impact |
MalwareLockerGoga | LockerGoga has encrypted files, including core Windows OS files, using RSA-OAEP MGF1 and then demanded Bitcoin be paid for the decryption key. |
| T1531 Account Access Removal |
MalwareLockerGoga | LockerGoga has been observed changing account passwords and logging off current users. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.