ATT&CKReferencesNCC Group WastedLocker June 2020

NCC Group WastedLocker June 2020

Antenucci, S., Pantazopoulos, N., Sandee, M. (2020, June 23). WastedLocker: A New Ransomware Variant Developed By The Evil Corp Group. Retrieved September 14, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software2

Campaigns0

None recorded.

Procedure examples17

TechniqueUsed byProcedure example
T1012
Query Registry
MalwareWastedLocker

WastedLocker checks for specific registry keys related to the UCOMIEnumConnections and IActiveScriptParseProcedure32 interfaces.

T1027.013
Encrypted/Encoded File
MalwareWastedLocker

The WastedLocker payload includes encrypted strings stored within the .bss section of the binary file.

T1027.016
Junk Code Insertion
MalwareWastedLocker

WastedLocker contains junk code to increase its entropy and hide the actual code.

T1059.003
Windows Command Shell
MalwareWastedLocker

WastedLocker has used cmd to execute commands on the system.

T1083
File and Directory Discovery
MalwareWastedLocker

WastedLocker can enumerate files and directories just prior to encryption.

T1106
Native API
MalwareWastedLocker

WastedLocker's custom crypter, CryptOne, leveraged the VirtualAlloc() API function to help execute the payload.

T1112
Modify Registry
MalwareWastedLocker

WastedLocker can modify registry values within the Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap registry key.

T1140
Deobfuscate/Decode Files or Information
MalwareWastedLocker

WastedLocker's custom cryptor, CryptOne, used an XOR based algorithm to decrypt the payload.

T1222.001
Windows Permissions
MalwareWastedLocker

WastedLocker has a command to take ownership of a file and reset the ACL permissions using the takeown.exe /F filepath command.

T1486
Data Encrypted for Impact
MalwareWastedLocker

WastedLocker can encrypt data and leave a ransom note.

T1490
Inhibit System Recovery
MalwareWastedLocker

WastedLocker can delete shadow volumes.

T1497.001
System Checks
MalwareWastedLocker

WastedLocker checked if UCOMIEnumConnections and IActiveScriptParseProcedure32 Registry keys were detected as part of its anti-analysis technique.

T1543.003
Windows Service
MalwareWastedLocker

WastedLocker created and established a service that runs until the encryption process is complete.

T1548.002
Bypass User Account Control
MalwareWastedLocker

WastedLocker can perform a UAC bypass if it is not executed with administrator rights or if the infected host runs Windows Vista or later.

T1564.001
Hidden Files and Directories
MalwareWastedLocker

WastedLocker has copied a random file from the Windows System32 folder to the %APPDATA% location under a different hidden filename.

T1569.002
Service Execution
MalwareWastedLocker

WastedLocker can execute itself as a service.

T1574.001
DLL
MalwareWastedLocker

WastedLocker has performed DLL hijacking before execution.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.