ATT&CKReferencesPalo Alto Unit 42 EKANS

Palo Alto Unit 42 EKANS

Hinchliffe, A. Santos, D. (2020, June 26). Threat Assessment: EKANS Ransomware. Retrieved February 9, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples3

TechniqueUsed byProcedure example
T1486
Data Encrypted for Impact
MalwareEKANS

EKANS uses standard encryption library functions to encrypt files.

T1489
Service Stop
MalwareEKANS

EKANS stops database, data backup solution, antivirus, and ICS-related processes.

T1490
Inhibit System Recovery
MalwareEKANS

EKANS removes backups of Volume Shadow Copies to disable any restoration capabilities.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.