ATT&CKReferencesSecureworks GandCrab and REvil September 2019

Secureworks GandCrab and REvil September 2019

Secureworks . (2019, September 24). REvil: The GandCrab Connection. Retrieved August 4, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples13

TechniqueUsed byProcedure example
T1027.011
Fileless Storage
MalwareREvil

REvil can save encryption parameters and system information in the Registry.

T1027.013
Encrypted/Encoded File
MalwareREvil

REvil has used encrypted strings and configuration files.

T1047
Windows Management Instrumentation
MalwareREvil

REvil can use WMI to monitor for and kill specific processes listed in its configuration file.

T1059.001
PowerShell
MalwareREvil

REvil has used PowerShell to delete volume shadow copies and download files.

T1071.001
Web Protocols
MalwareREvil

REvil has used HTTP and HTTPS in communication with C2.

T1082
System Information Discovery
MalwareREvil

REvil can identify the username, machine name, system language, keyboard layout, and OS version on a compromised host.

T1083
File and Directory Discovery
MalwareREvil

REvil has the ability to identify specific files and directories that are not to be encrypted.

T1112
Modify Registry
MalwareREvil

REvil can modify the Registry to save encryption parameters and system information.

T1189
Drive-by Compromise
MalwareREvil

REvil has infected victim machines through compromised websites and exploit kits.

T1195.002
Compromise Software Supply Chain
GroupGOLD SOUTHFIELD

GOLD SOUTHFIELD has distributed ransomware by backdooring software installers via a strategic web compromise of the site hosting Italian WinRAR.

T1485
Data Destruction
MalwareREvil

REvil has the capability to destroy files and folders.

T1490
Inhibit System Recovery
MalwareREvil

REvil can use vssadmin to delete volume shadow copies and bcdedit to disable recovery features.

T1680
Local Storage Discovery
MalwareREvil

REvil can identify system drive information on a compromised host.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.