DHS/CISA. (2020, October 28). Ransomware Activity Targeting the Healthcare and Public Health Sector. Retrieved October 28, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1021.001 Remote Desktop Protocol |
GroupWizard Spider | Wizard Spider has used RDP for lateral movement and to deploy ransomware interactively. |
| T1021.006 Windows Remote Management |
GroupWizard Spider | Wizard Spider has used Window Remote Management to move laterally through a victim network. |
| T1047 Windows Management Instrumentation |
GroupWizard Spider | Wizard Spider has used WMI and LDAP queries for network discovery and to move laterally. Wizard Spider has also used batch scripts to leverage WMIC to deploy ransomware. |
| T1053.005 Scheduled Task |
GroupWizard Spider | Wizard Spider has used scheduled tasks to establish persistence for TrickBot and other malware. |
| T1055.001 Dynamic-link Library Injection |
GroupWizard Spider | Wizard Spider has injected malicious DLLs into memory with read, write, and execute permissions. |
| T1059.001 PowerShell |
GroupWizard Spider | Wizard Spider has used macros to execute PowerShell scripts to download malware on victim's machines. It has also used PowerShell to execute commands and move laterally through a victim network. |
| T1135 Network Share Discovery |
GroupWizard Spider | Wizard Spider has used the “net view” command to locate mapped network shares. |
| T1204.001 Malicious Link |
GroupWizard Spider | Wizard Spider has lured victims into clicking a malicious link delivered through spearphishing. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupWizard Spider | Wizard Spider has established persistence via the Registry key |
| T1558.003 Kerberoasting |
GroupWizard Spider | Wizard Spider has used Rubeus, MimiKatz Kerberos module, and the Invoke-Kerberoast cmdlet to steal AES hashes. |
| T1566.002 Spearphishing Link |
GroupWizard Spider | Wizard Spider has sent phishing emails containing a link to an actor-controlled Google Drive document or other free online file hosting services. |
| T1685 Disable or Modify Tools |
GroupWizard Spider | Wizard Spider has shut down or uninstalled security applications on victim systems that might prevent ransomware from executing. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.