ATT&CKReferencesCrowdStrike Wizard Spider October 2020

CrowdStrike Wizard Spider October 2020

Podlosky, A., Hanel, A. et al. (2020, October 16). WIZARD SPIDER Update: Resilient, Reactive and Resolute. Retrieved June 15, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples13

TechniqueUsed byProcedure example
T1018
Remote System Discovery
MalwareConti

Conti has the ability to discover hosts on a target network.

T1027
Obfuscated Files or Information
MalwareRyuk

Ryuk can use anti-disassembly and code transformation obfuscation techniques.

T1027
Obfuscated Files or Information
MalwareConti

Conti can use compiler-based obfuscation for its code, encrypt DLLs, and hide Windows API calls.

T1027.013
Encrypted/Encoded File
MalwareBazar

Bazar has used XOR, RSA2, and RC4 encrypted files.

T1036.005
Match Legitimate Resource Name or Location
MalwareBazar

The Bazar loader has named malicious shortcuts "adobe" and mimicked communications software.

T1059.001
PowerShell
MalwareBazar

Bazar can execute a PowerShell script received from C2.

T1105
Ingress Tool Transfer
MalwareBazar

Bazar can download and deploy additional payloads, including ransomware and post-exploitation frameworks such as Cobalt Strike.

T1135
Network Share Discovery
MalwareConti

Conti can enumerate remote open SMB network shares using NetShareEnum().

T1204.001
Malicious Link
MalwareBazar

Bazar can gain execution after a user clicks on a malicious link to decoy landing pages hosted on Google Docs.

T1204.002
Malicious File
GroupWizard Spider

Wizard Spider has lured victims to execute malware with spearphishing attachments containing macros to download either Emotet, Bokbot, TrickBot, or Bazar.

T1486
Data Encrypted for Impact
MalwareConti

Conti can use CreateIoCompletionPort(), PostQueuedCompletionStatus(), and GetQueuedCompletionPort() to rapidly encrypt files, excluding those with the extensions of .exe, .dll, and .lnk. It has used a different AES-256 encryption key per file with a bundled RAS-4096 public encryption key that is unique for each victim. Conti can use “Windows Restart Manager” to ensure files are unlocked and open for encryption.

T1486
Data Encrypted for Impact
MalwareRyuk

Ryuk has used a combination of symmetric (AES) and asymmetric (RSA) encryption to encrypt files. Files have been encrypted with their own AES key and given a file extension of .RYK. Encrypted directories have had a ransom note of RyukReadMe.txt written to the directory.

T1566.002
Spearphishing Link
MalwareBazar

Bazar has been spread via emails with embedded malicious links.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.