Podlosky, A., Hanel, A. et al. (2020, October 16). WIZARD SPIDER Update: Resilient, Reactive and Resolute. Retrieved June 15, 2021.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1018 Remote System Discovery |
MalwareConti | Conti has the ability to discover hosts on a target network. |
| T1027 Obfuscated Files or Information |
MalwareRyuk | Ryuk can use anti-disassembly and code transformation obfuscation techniques. |
| T1027 Obfuscated Files or Information |
MalwareConti | Conti can use compiler-based obfuscation for its code, encrypt DLLs, and hide Windows API calls. |
| T1027.013 Encrypted/Encoded File |
MalwareBazar | Bazar has used XOR, RSA2, and RC4 encrypted files. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareBazar | The Bazar loader has named malicious shortcuts "adobe" and mimicked communications software. |
| T1059.001 PowerShell |
MalwareBazar | Bazar can execute a PowerShell script received from C2. |
| T1105 Ingress Tool Transfer |
MalwareBazar | Bazar can download and deploy additional payloads, including ransomware and post-exploitation frameworks such as Cobalt Strike. |
| T1135 Network Share Discovery |
MalwareConti | Conti can enumerate remote open SMB network shares using |
| T1204.001 Malicious Link |
MalwareBazar | Bazar can gain execution after a user clicks on a malicious link to decoy landing pages hosted on Google Docs. |
| T1204.002 Malicious File |
GroupWizard Spider | Wizard Spider has lured victims to execute malware with spearphishing attachments containing macros to download either Emotet, Bokbot, TrickBot, or Bazar. |
| T1486 Data Encrypted for Impact |
MalwareConti | Conti can use |
| T1486 Data Encrypted for Impact |
MalwareRyuk | Ryuk has used a combination of symmetric (AES) and asymmetric (RSA) encryption to encrypt files. Files have been encrypted with their own AES key and given a file extension of .RYK. Encrypted directories have had a ransom note of RyukReadMe.txt written to the directory. |
| T1566.002 Spearphishing Link |
MalwareBazar | Bazar has been spread via emails with embedded malicious links. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.