ATT&CKReferencesDHS/CISA Ransomware Targeting Healthcare October 2020

DHS/CISA Ransomware Targeting Healthcare October 2020

DHS/CISA. (2020, October 28). Ransomware Activity Targeting the Healthcare and Public Health Sector. Retrieved October 28, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples12

TechniqueUsed byProcedure example
T1021.001
Remote Desktop Protocol
GroupWizard Spider

Wizard Spider has used RDP for lateral movement and to deploy ransomware interactively.

T1021.006
Windows Remote Management
GroupWizard Spider

Wizard Spider has used Window Remote Management to move laterally through a victim network.

T1047
Windows Management Instrumentation
GroupWizard Spider

Wizard Spider has used WMI and LDAP queries for network discovery and to move laterally. Wizard Spider has also used batch scripts to leverage WMIC to deploy ransomware.

T1053.005
Scheduled Task
GroupWizard Spider

Wizard Spider has used scheduled tasks to establish persistence for TrickBot and other malware.

T1055.001
Dynamic-link Library Injection
GroupWizard Spider

Wizard Spider has injected malicious DLLs into memory with read, write, and execute permissions.

T1059.001
PowerShell
GroupWizard Spider

Wizard Spider has used macros to execute PowerShell scripts to download malware on victim's machines. It has also used PowerShell to execute commands and move laterally through a victim network.

T1135
Network Share Discovery
GroupWizard Spider

Wizard Spider has used the “net view” command to locate mapped network shares.

T1204.001
Malicious Link
GroupWizard Spider

Wizard Spider has lured victims into clicking a malicious link delivered through spearphishing.

T1547.001
Registry Run Keys / Startup Folder
GroupWizard Spider

Wizard Spider has established persistence via the Registry key HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run and a shortcut within the startup folder.

T1558.003
Kerberoasting
GroupWizard Spider

Wizard Spider has used Rubeus, MimiKatz Kerberos module, and the Invoke-Kerberoast cmdlet to steal AES hashes.

T1566.002
Spearphishing Link
GroupWizard Spider

Wizard Spider has sent phishing emails containing a link to an actor-controlled Google Drive document or other free online file hosting services.

T1685
Disable or Modify Tools
GroupWizard Spider

Wizard Spider has shut down or uninstalled security applications on victim systems that might prevent ransomware from executing.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.