Walter, J.. (2020, July 23). WastedLocker Ransomware: Abusing ADS and NTFS File Attributes. Retrieved September 14, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1120 Peripheral Device Discovery |
MalwareWastedLocker | WastedLocker can enumerate removable drives prior to the encryption process. |
| T1135 Network Share Discovery |
MalwareWastedLocker | WastedLocker can identify network adjacent and accessible drives. |
| T1486 Data Encrypted for Impact |
MalwareWastedLocker | WastedLocker can encrypt data and leave a ransom note. |
| T1490 Inhibit System Recovery |
MalwareWastedLocker | WastedLocker can delete shadow volumes. |
| T1564.004 NTFS File Attributes |
MalwareWastedLocker | WastedLocker has the ability to save and execute files as an alternate data stream (ADS). |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.