ATT&CKReferencesTalos Nyetya June 2017

Talos Nyetya June 2017

Chiu, A. (2016, June 27). New Ransomware Variant "Nyetya" Compromises Systems Worldwide. Retrieved March 26, 2019.

Open the source

Techniques1

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples12

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
MalwareNotPetya

NotPetya contains a modified version of Mimikatz to help gather credentials that are later used for lateral movement.

T1021.002
SMB/Windows Admin Shares
MalwareNotPetya

NotPetya can use PsExec, which interacts with the ADMIN$ network share to execute commands on remote systems.

T1036
Masquerading
MalwareNotPetya

NotPetya drops PsExec with the filename dllhost.dat.

T1047
Windows Management Instrumentation
MalwareNotPetya

NotPetya can use wmic to help propagate itself across a network.

T1053.005
Scheduled Task
MalwareNotPetya

NotPetya creates a task to reboot the system one hour after infection.

T1078.003
Local Accounts
MalwareNotPetya

NotPetya can use valid credentials with PsExec or wmic to spread itself to remote systems.

T1210
Exploitation of Remote Services
MalwareNotPetya

NotPetya can use two exploits in SMBv1, EternalBlue and EternalRomance, to spread itself to other remote systems on the network.

T1218.011
Rundll32
MalwareNotPetya

NotPetya uses rundll32.exe to install itself on remote systems when accessed via PsExec or wmic.

T1486
Data Encrypted for Impact
MalwareNotPetya

NotPetya encrypts user files and disk structures like the MBR with 2048-bit RSA.

T1529
System Shutdown/Reboot
MalwareNotPetya

NotPetya will reboot the system one hour after infection.

T1569.002
Service Execution
MalwareNotPetya

NotPetya can use PsExec to help propagate itself across a network.

T1685.005
Clear Windows Event Logs
MalwareNotPetya

NotPetya uses wevtutil to clear the Windows event logs.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.