ATT&CKReferencesSymantec WastedLocker June 2020

Symantec WastedLocker June 2020

Symantec Threat Intelligence. (2020, June 25). WastedLocker: Symantec Identifies Wave of Attacks Against U.S. Organizations. Retrieved May 20, 2021.

Open the source

Techniques1

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples15

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupIndrik Spider

Indrik Spider used Cobalt Strike to carry out credential dumping using ProcDump.

T1007
System Service Discovery
GroupIndrik Spider

Indrik Spider has used the win32_service WMI class to retrieve a list of services from the system.

T1018
Remote System Discovery
GroupIndrik Spider

Indrik Spider has used PowerView to enumerate all Windows Server, Windows Server 2003, and Windows 7 instances in the Active Directory database.

T1047
Windows Management Instrumentation
GroupIndrik Spider

Indrik Spider has used WMIC to execute commands on remote computers.

T1059.001
PowerShell
GroupIndrik Spider

Indrik Spider has used PowerShell Empire for execution of malware.

T1059.007
JavaScript
GroupIndrik Spider

Indrik Spider has used malicious JavaScript files for several components of their attack.

T1074.001
Local Data Staging
GroupIndrik Spider

Indrik Spider has stored collected data in a .tmp file.

T1105
Ingress Tool Transfer
GroupIndrik Spider

Indrik Spider has downloaded additional scripts, malware, and tools onto a compromised host.

T1136
Create Account
GroupIndrik Spider

Indrik Spider used wmic.exe to add a new user to the system.

T1204.002
Malicious File
GroupIndrik Spider

Indrik Spider has attempted to get users to click on a malicious zipped file.

T1486
Data Encrypted for Impact
MalwareWastedLocker

WastedLocker can encrypt data and leave a ransom note.

T1489
Service Stop
GroupIndrik Spider

Indrik Spider has used PsExec to stop services prior to the execution of ransomware.

T1490
Inhibit System Recovery
MalwareWastedLocker

WastedLocker can delete shadow volumes.

T1685
Disable or Modify Tools
GroupIndrik Spider

Indrik Spider used PsExec to leverage Windows Defender to disable scanning of all downloaded files and to restrict real-time monitoring. Indrik Spider has used `MpCmdRun` to revert the definitions in Microsoft Defender. Additionally, Indrik Spider has used WMI to stop or uninstall and reset anti-virus products and other defensive services.

T1685.005
Clear Windows Event Logs
GroupIndrik Spider

Indrik Spider has used Cobalt Strike to empty log files. Additionally, Indrik Spider has cleared all event logs using `wevutil`.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.