MSTIC. (2022, October 14). New “Prestige” ransomware impacts organizations in Ukraine and Poland. Retrieved January 19, 2023.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupSandworm Team | Sandworm Team has used its plainpwd tool, a modified version of Mimikatz, and comsvcs.dll to dump Windows credentials from system memory. |
| T1003.003 NTDS |
GroupSandworm Team | Sandworm Team has used `ntdsutil.exe` to back up the Active Directory database, likely for credential access. |
| T1021.002 SMB/Windows Admin Shares |
GroupSandworm Team | Sandworm Team has copied payloads to the `ADMIN$` share of remote systems and run |
| T1047 Windows Management Instrumentation |
GroupSandworm Team | Sandworm Team has used Impacket’s WMIexec module for remote code execution and VBScript to run WMI queries. |
| T1053.005 Scheduled Task |
MalwarePrestige | Prestige has been executed on a target system through a scheduled task created by Sandworm Team using Impacket. |
| T1059.001 PowerShell |
MalwarePrestige | Prestige can use PowerShell for payload execution on targeted systems. |
| T1072 Software Deployment Tools |
GroupSandworm Team | Sandworm Team has used the commercially available tool RemoteExec for agentless remote code execution. |
| T1078.002 Domain Accounts |
GroupSandworm Team | Sandworm Team has used stolen credentials to access administrative accounts within the domain. |
| T1083 File and Directory Discovery |
MalwarePrestige | Prestige can traverse the file system to discover files to encrypt by identifying specific extensions defined in a hardcoded list. |
| T1106 Native API |
MalwarePrestige | Prestige has used the `Wow64DisableWow64FsRedirection()` and `Wow64RevertWow64FsRedirection()` functions to disable and restore file system redirection. |
| T1106 Native API |
GroupSandworm Team | Sandworm Team uses Prestige to disable and restore file system redirection by using the following functions: `Wow64DisableWow64FsRedirection()` and `Wow64RevertWow64FsRedirection()`. |
| T1112 Modify Registry |
MalwarePrestige | Prestige has the ability to register new registry keys for a new extension handler via `HKCR\.enc` and `HKCR\enc\shell\open\command`. |
| T1219 Remote Access Tools |
GroupSandworm Team | Sandworm Team has used remote administration tools or remote industrial control system client software for execution and to maliciously release electricity breakers. |
| T1484.001 Group Policy Modification |
MalwarePrestige | Prestige has been deployed using the Default Domain Group Policy Object from an Active Directory Domain Controller. |
| T1486 Data Encrypted for Impact |
MalwarePrestige | Prestige has leveraged the CryptoPP C++ library to encrypt files on target systems using AES and appended filenames with `.enc`. |
| T1486 Data Encrypted for Impact |
GroupSandworm Team | Sandworm Team has used Prestige ransomware to encrypt data at targeted organizations in transportation and related logistics industries in Ukraine and Poland. |
| T1489 Service Stop |
MalwarePrestige | Prestige has attempted to stop the MSSQL Windows service to ensure successful encryption using `C:\Windows\System32\net.exe stop MSSQLSERVER`. |
| T1489 Service Stop |
GroupSandworm Team | Sandworm Team attempts to stop the MSSQL Windows service to ensure successful encryption of locked files. |
| T1490 Inhibit System Recovery |
GroupSandworm Team | Sandworm Team uses Prestige to delete the backup catalog from the target system using: `C:\Windows\System32\wbadmin.exe delete catalog -quiet` and to delete volume shadow copies using: `C:\Windows\System32\vssadmin.exe delete shadows /all /quiet`. |
| T1490 Inhibit System Recovery |
MalwarePrestige | Prestige can delete the backup catalog from the target system using: `c:\Windows\System32\wbadmin.exe delete catalog -quiet` and can also delete volume shadow copies using: `\Windows\System32\vssadmin.exe delete shadows /all /quiet`. |
| T1570 Lateral Tool Transfer |
GroupSandworm Team | Sandworm Team has used `move` to transfer files to a network share and has copied payloads--such as Prestige ransomware--to an Active Directory Domain Controller and distributed via the Default Domain Group Policy Object. Additionally, Sandworm Team has transferred an ISO file into the OT network to gain initial access. |
| T1588.002 Tool |
GroupSandworm Team | Sandworm Team has acquired open-source tools for their operations, including Invoke-PSImage, which was used to establish an encrypted channel from a compromised host to Sandworm Team's C2 server in preparation for the 2018 Winter Olympics attack, as well as Impacket and RemoteExec, which were used in their 2022 Prestige operations. Additionally, Sandworm Team has used Empire, Cobalt Strike and PoshC2. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.