ATT&CKReferencesMicrosoft Prestige ransomware October 2022

Microsoft Prestige ransomware October 2022

MSTIC. (2022, October 14). New “Prestige” ransomware impacts organizations in Ukraine and Poland. Retrieved January 19, 2023.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples22

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupSandworm Team

Sandworm Team has used its plainpwd tool, a modified version of Mimikatz, and comsvcs.dll to dump Windows credentials from system memory.

T1003.003
NTDS
GroupSandworm Team

Sandworm Team has used `ntdsutil.exe` to back up the Active Directory database, likely for credential access.

T1021.002
SMB/Windows Admin Shares
GroupSandworm Team

Sandworm Team has copied payloads to the `ADMIN$` share of remote systems and run net use to connect to network shares.

T1047
Windows Management Instrumentation
GroupSandworm Team

Sandworm Team has used Impacket’s WMIexec module for remote code execution and VBScript to run WMI queries.

T1053.005
Scheduled Task
MalwarePrestige

Prestige has been executed on a target system through a scheduled task created by Sandworm Team using Impacket.

T1059.001
PowerShell
MalwarePrestige

Prestige can use PowerShell for payload execution on targeted systems.

T1072
Software Deployment Tools
GroupSandworm Team

Sandworm Team has used the commercially available tool RemoteExec for agentless remote code execution.

T1078.002
Domain Accounts
GroupSandworm Team

Sandworm Team has used stolen credentials to access administrative accounts within the domain.

T1083
File and Directory Discovery
MalwarePrestige

Prestige can traverse the file system to discover files to encrypt by identifying specific extensions defined in a hardcoded list.

T1106
Native API
MalwarePrestige

Prestige has used the `Wow64DisableWow64FsRedirection()` and `Wow64RevertWow64FsRedirection()` functions to disable and restore file system redirection.

T1106
Native API
GroupSandworm Team

Sandworm Team uses Prestige to disable and restore file system redirection by using the following functions: `Wow64DisableWow64FsRedirection()` and `Wow64RevertWow64FsRedirection()`.

T1112
Modify Registry
MalwarePrestige

Prestige has the ability to register new registry keys for a new extension handler via `HKCR\.enc` and `HKCR\enc\shell\open\command`.

T1219
Remote Access Tools
GroupSandworm Team

Sandworm Team has used remote administration tools or remote industrial control system client software for execution and to maliciously release electricity breakers.

T1484.001
Group Policy Modification
MalwarePrestige

Prestige has been deployed using the Default Domain Group Policy Object from an Active Directory Domain Controller.

T1486
Data Encrypted for Impact
MalwarePrestige

Prestige has leveraged the CryptoPP C++ library to encrypt files on target systems using AES and appended filenames with `.enc`.

T1486
Data Encrypted for Impact
GroupSandworm Team

Sandworm Team has used Prestige ransomware to encrypt data at targeted organizations in transportation and related logistics industries in Ukraine and Poland.

T1489
Service Stop
MalwarePrestige

Prestige has attempted to stop the MSSQL Windows service to ensure successful encryption using `C:\Windows\System32\net.exe stop MSSQLSERVER`.

T1489
Service Stop
GroupSandworm Team

Sandworm Team attempts to stop the MSSQL Windows service to ensure successful encryption of locked files.

T1490
Inhibit System Recovery
GroupSandworm Team

Sandworm Team uses Prestige to delete the backup catalog from the target system using: `C:\Windows\System32\wbadmin.exe delete catalog -quiet` and to delete volume shadow copies using: `C:\Windows\System32\vssadmin.exe delete shadows /all /quiet`.

T1490
Inhibit System Recovery
MalwarePrestige

Prestige can delete the backup catalog from the target system using: `c:\Windows\System32\wbadmin.exe delete catalog -quiet` and can also delete volume shadow copies using: `\Windows\System32\vssadmin.exe delete shadows /all /quiet`.

T1570
Lateral Tool Transfer
GroupSandworm Team

Sandworm Team has used `move` to transfer files to a network share and has copied payloads--such as Prestige ransomware--to an Active Directory Domain Controller and distributed via the Default Domain Group Policy Object. Additionally, Sandworm Team has transferred an ISO file into the OT network to gain initial access.

T1588.002
Tool
GroupSandworm Team

Sandworm Team has acquired open-source tools for their operations, including Invoke-PSImage, which was used to establish an encrypted channel from a compromised host to Sandworm Team's C2 server in preparation for the 2018 Winter Olympics attack, as well as Impacket and RemoteExec, which were used in their 2022 Prestige operations. Additionally, Sandworm Team has used Empire, Cobalt Strike and PoshC2.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.