Symantec Threat Intelligence. (2020, June 25). WastedLocker: Symantec Identifies Wave of Attacks Against U.S. Organizations. Retrieved May 20, 2021.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupIndrik Spider | Indrik Spider used Cobalt Strike to carry out credential dumping using ProcDump. |
| T1007 System Service Discovery |
GroupIndrik Spider | Indrik Spider has used the win32_service WMI class to retrieve a list of services from the system. |
| T1018 Remote System Discovery |
GroupIndrik Spider | Indrik Spider has used PowerView to enumerate all Windows Server, Windows Server 2003, and Windows 7 instances in the Active Directory database. |
| T1047 Windows Management Instrumentation |
GroupIndrik Spider | Indrik Spider has used WMIC to execute commands on remote computers. |
| T1059.001 PowerShell |
GroupIndrik Spider | Indrik Spider has used PowerShell Empire for execution of malware. |
| T1059.007 JavaScript |
GroupIndrik Spider | Indrik Spider has used malicious JavaScript files for several components of their attack. |
| T1074.001 Local Data Staging |
GroupIndrik Spider | Indrik Spider has stored collected data in a .tmp file. |
| T1105 Ingress Tool Transfer |
GroupIndrik Spider | Indrik Spider has downloaded additional scripts, malware, and tools onto a compromised host. |
| T1136 Create Account |
GroupIndrik Spider | Indrik Spider used |
| T1204.002 Malicious File |
GroupIndrik Spider | Indrik Spider has attempted to get users to click on a malicious zipped file. |
| T1486 Data Encrypted for Impact |
MalwareWastedLocker | WastedLocker can encrypt data and leave a ransom note. |
| T1489 Service Stop |
GroupIndrik Spider | Indrik Spider has used PsExec to stop services prior to the execution of ransomware. |
| T1490 Inhibit System Recovery |
MalwareWastedLocker | WastedLocker can delete shadow volumes. |
| T1685 Disable or Modify Tools |
GroupIndrik Spider | Indrik Spider used PsExec to leverage Windows Defender to disable scanning of all downloaded files and to restrict real-time monitoring. Indrik Spider has used `MpCmdRun` to revert the definitions in Microsoft Defender. Additionally, Indrik Spider has used WMI to stop or uninstall and reset anti-virus products and other defensive services. |
| T1685.005 Clear Windows Event Logs |
GroupIndrik Spider | Indrik Spider has used Cobalt Strike to empty log files. Additionally, Indrik Spider has cleared all event logs using `wevutil`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.