Alfano, V. et al. (2025, February 12). RansomHub Never Sleeps Episode 1: The evolution of modern ransomware. Retrieved March 17, 2025.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1018 Remote System Discovery |
MalwareRansomHub | RansomHub can enumerate all accessible machines from the infected system. |
| T1021.002 SMB/Windows Admin Shares |
MalwareRansomHub | RansomHub can use credentials provided in its configuration to move laterally from the infected machine over SMBv2. |
| T1027.013 Encrypted/Encoded File |
MalwareRansomHub | RansomHub has an encrypted configuration file. |
| T1059.001 PowerShell |
MalwareRansomHub | RansomHub can use PowerShell to delete volume shadow copies. |
| T1059.003 Windows Command Shell |
MalwareRansomHub | RansomHub can use `cmd.exe` to execute multiple commands on infected hosts. |
| T1070.004 File Deletion |
MalwareRansomHub | RansomHub has the ability to self-delete. |
| T1082 System Information Discovery |
MalwareRansomHub | RansomHub can retrieve information about virtual machines. |
| T1083 File and Directory Discovery |
MalwareRansomHub | RansomHub has the ability to only encrypt specific files. |
| T1090 Proxy |
MalwareRansomHub | RansomHub can use a proxy to connect to remote SFTP servers. |
| T1135 Network Share Discovery |
MalwareRansomHub | RansomHub has the ability to target specific network shares for encryption. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareRansomHub | RansomHub can use a provided passphrase to decrypt its configuration file. |
| T1480 Execution Guardrails |
MalwareRansomHub | RansomHub will terminate without proceeding to encryption if the infected machine is on a list of allowlisted machines specified in its configuration. |
| T1486 Data Encrypted for Impact |
MalwareRansomHub | RansomHub can use Elliptic Curve Encryption to encrypt files on targeted systems. RansomHub can also skip content at regular intervals (ex. encrypt 1 MB, skip 3 MB) to optomize performance and enable faster encryption for large files. |
| T1489 Service Stop |
MalwareRansomHub | RansomHub has the ability to terminate specified services. |
| T1490 Inhibit System Recovery |
MalwareRansomHub | RansomHub has used `vssadmin.exe` to delete volume shadow copies. |
| T1497.003 Time Based Checks |
MalwareRansomHub | RansomHub can sleep for a set number of minutes before beginning execution. |
| T1547.001 Registry Run Keys / Startup Folder |
MalwareRansomHub | RansomHub has created an autorun Registry key through the `-safeboot-instance -pass` command line argument. |
| T1685.005 Clear Windows Event Logs |
MalwareRansomHub | RansomHub can delete events from the Security, System, and Application logs. |
| T1688 Safe Mode Boot |
MalwareRansomHub | RansomHub can reboot targeted systems into Safe Mode prior to encryption. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.