Frankoff, S., Hartley, B. (2018, November 14). Big Game Hunting: The Evolution of INDRIK SPIDER From Dridex Wire Fraud to BitPaymer Targeted Ransomware. Retrieved January 6, 2021.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1007 System Service Discovery |
MalwareBitPaymer | BitPaymer can enumerate existing Windows services on the host that are configured to run as LocalSystem. |
| T1012 Query Registry |
MalwareBitPaymer | BitPaymer can use the RegEnumKeyW to iterate through Registry keys. |
| T1018 Remote System Discovery |
MalwareBitPaymer | BitPaymer can use |
| T1027.013 Encrypted/Encoded File |
MalwareBitPaymer | BitPaymer has used RC4-encrypted strings and string hashes to avoid identifiable strings within the binary. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupIndrik Spider | Indrik Spider used fake updates for FlashPlayer plugin and Google Chrome as initial infection vectors. |
| T1059.001 PowerShell |
GroupIndrik Spider | Indrik Spider has used PowerShell Empire for execution of malware. |
| T1059.003 Windows Command Shell |
GroupIndrik Spider | Indrik Spider has used batch scripts on victim's machines. |
| T1070.006 Timestomp |
MalwareBitPaymer | BitPaymer can modify the timestamp of an executable so that it can be identified and restored by the decryption tool. |
| T1078.002 Domain Accounts |
GroupIndrik Spider | Indrik Spider has collected credentials from infected systems, including domain accounts. |
| T1087.001 Local Account |
MalwareBitPaymer | BitPaymer can enumerate the sessions for each user logged onto the infected host. |
| T1105 Ingress Tool Transfer |
GroupIndrik Spider | Indrik Spider has downloaded additional scripts, malware, and tools onto a compromised host. |
| T1106 Native API |
MalwareBitPaymer | BitPaymer has used dynamic API resolution to avoid identifiable strings within the binary, including |
| T1112 Modify Registry |
MalwareBitPaymer | BitPaymer can set values in the Registry to help in execution. |
| T1134.001 Token Impersonation/Theft |
MalwareBitPaymer | BitPaymer can use the tokens of users to create processes on infected systems. |
| T1135 Network Share Discovery |
MalwareBitPaymer | BitPaymer can search for network shares on the domain or workgroup using |
| T1222.001 Windows Permissions |
MalwareBitPaymer | BitPaymer can use |
| T1480 Execution Guardrails |
MalwareBitPaymer | BitPaymer compares file names and paths to a list of excluded names and directory names during encryption. |
| T1484.001 Group Policy Modification |
GroupIndrik Spider | Indrik Spider has used Group Policy Objects to deploy batch scripts. |
| T1486 Data Encrypted for Impact |
MalwareBitPaymer | BitPaymer can import a hard-coded RSA 1024-bit public key, generate a 128-bit RC4 key for each file, and encrypt the file in place, appending |
| T1486 Data Encrypted for Impact |
GroupIndrik Spider | Indrik Spider has encrypted domain-controlled systems using BitPaymer. Additionally, Indrik Spider used PsExec to execute a ransomware script. |
| T1490 Inhibit System Recovery |
MalwareBitPaymer | BitPaymer attempts to remove the backup shadow files from the host using |
| T1543.003 Windows Service |
MalwareBitPaymer | BitPaymer has attempted to install itself as a service to maintain persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareBitPaymer | BitPaymer has set the run key |
| T1548.002 Bypass User Account Control |
MalwareBitPaymer | BitPaymer can suppress UAC prompts by setting the |
| T1564.004 NTFS File Attributes |
MalwareBitPaymer | BitPaymer has copied itself to the |
| T1584.004 Server |
GroupIndrik Spider | Indrik Spider has served fake updates via legitimate websites that have been compromised. |
| T1585.002 Email Accounts |
GroupIndrik Spider | Indrik Spider has created email accounts to communicate with their ransomware victims, to include providing payment and decryption details. |
| T1587.001 Malware |
GroupIndrik Spider | Indrik Spider has developed malware for their operations, including ransomware such as BitPaymer and WastedLocker. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.