ATT&CKReferencesCrowdstrike Indrik November 2018

Crowdstrike Indrik November 2018

Frankoff, S., Hartley, B. (2018, November 14). Big Game Hunting: The Evolution of INDRIK SPIDER From Dridex Wire Fraud to BitPaymer Targeted Ransomware. Retrieved January 6, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples28

TechniqueUsed byProcedure example
T1007
System Service Discovery
MalwareBitPaymer

BitPaymer can enumerate existing Windows services on the host that are configured to run as LocalSystem.

T1012
Query Registry
MalwareBitPaymer

BitPaymer can use the RegEnumKeyW to iterate through Registry keys.

T1018
Remote System Discovery
MalwareBitPaymer

BitPaymer can use net view to discover remote systems.

T1027.013
Encrypted/Encoded File
MalwareBitPaymer

BitPaymer has used RC4-encrypted strings and string hashes to avoid identifiable strings within the binary.

T1036.005
Match Legitimate Resource Name or Location
GroupIndrik Spider

Indrik Spider used fake updates for FlashPlayer plugin and Google Chrome as initial infection vectors.

T1059.001
PowerShell
GroupIndrik Spider

Indrik Spider has used PowerShell Empire for execution of malware.

T1059.003
Windows Command Shell
GroupIndrik Spider

Indrik Spider has used batch scripts on victim's machines.

T1070.006
Timestomp
MalwareBitPaymer

BitPaymer can modify the timestamp of an executable so that it can be identified and restored by the decryption tool.

T1078.002
Domain Accounts
GroupIndrik Spider

Indrik Spider has collected credentials from infected systems, including domain accounts.

T1087.001
Local Account
MalwareBitPaymer

BitPaymer can enumerate the sessions for each user logged onto the infected host.

T1105
Ingress Tool Transfer
GroupIndrik Spider

Indrik Spider has downloaded additional scripts, malware, and tools onto a compromised host.

T1106
Native API
MalwareBitPaymer

BitPaymer has used dynamic API resolution to avoid identifiable strings within the binary, including RegEnumKeyW.

T1112
Modify Registry
MalwareBitPaymer

BitPaymer can set values in the Registry to help in execution.

T1134.001
Token Impersonation/Theft
MalwareBitPaymer

BitPaymer can use the tokens of users to create processes on infected systems.

T1135
Network Share Discovery
MalwareBitPaymer

BitPaymer can search for network shares on the domain or workgroup using net view <host>.

T1222.001
Windows Permissions
MalwareBitPaymer

BitPaymer can use icacls /reset and takeown /F to reset a targeted executable's permissions and then take ownership.

T1480
Execution Guardrails
MalwareBitPaymer

BitPaymer compares file names and paths to a list of excluded names and directory names during encryption.

T1484.001
Group Policy Modification
GroupIndrik Spider

Indrik Spider has used Group Policy Objects to deploy batch scripts.

T1486
Data Encrypted for Impact
MalwareBitPaymer

BitPaymer can import a hard-coded RSA 1024-bit public key, generate a 128-bit RC4 key for each file, and encrypt the file in place, appending .locked to the filename.

T1486
Data Encrypted for Impact
GroupIndrik Spider

Indrik Spider has encrypted domain-controlled systems using BitPaymer. Additionally, Indrik Spider used PsExec to execute a ransomware script.

T1490
Inhibit System Recovery
MalwareBitPaymer

BitPaymer attempts to remove the backup shadow files from the host using vssadmin.exe Delete Shadows /All /Quiet.

T1543.003
Windows Service
MalwareBitPaymer

BitPaymer has attempted to install itself as a service to maintain persistence.

T1547.001
Registry Run Keys / Startup Folder
MalwareBitPaymer

BitPaymer has set the run key HKCU\Software\Microsoft\Windows\CurrentVersion\Run for persistence.

T1548.002
Bypass User Account Control
MalwareBitPaymer

BitPaymer can suppress UAC prompts by setting the HKCU\Software\Classes\ms-settings\shell\open\command registry key on Windows 10 or HKCU\Software\Classes\mscfile\shell\open\command on Windows 7 and launching the eventvwr.msc process, which launches BitPaymer with elevated privileges.

T1564.004
NTFS File Attributes
MalwareBitPaymer

BitPaymer has copied itself to the :bin alternate data stream of a newly created file.

T1584.004
Server
GroupIndrik Spider

Indrik Spider has served fake updates via legitimate websites that have been compromised.

T1585.002
Email Accounts
GroupIndrik Spider

Indrik Spider has created email accounts to communicate with their ransomware victims, to include providing payment and decryption details.

T1587.001
Malware
GroupIndrik Spider

Indrik Spider has developed malware for their operations, including ransomware such as BitPaymer and WastedLocker.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.