ATT&CKReferencesDragos EKANS

Dragos EKANS

Dragos. (2020, February 3). EKANS Ransomware and ICS Operations. Retrieved February 9, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1036.005
Match Legitimate Resource Name or Location
MalwareEKANS

EKANS has been disguised as update.exe to appear as a valid executable.

T1047
Windows Management Instrumentation
MalwareEKANS

EKANS can use Windows Mangement Instrumentation (WMI) calls to execute operations.

T1057
Process Discovery
MalwareEKANS

EKANS looks for processes from a hard-coded list.

T1486
Data Encrypted for Impact
MalwareEKANS

EKANS uses standard encryption library functions to encrypt files.

T1489
Service Stop
MalwareEKANS

EKANS stops database, data backup solution, antivirus, and ICS-related processes.

T1490
Inhibit System Recovery
MalwareEKANS

EKANS removes backups of Volume Shadow Copies to disable any restoration capabilities.

T1685
Disable or Modify Tools
MalwareEKANS

EKANS stops processes related to security and management software.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.