Rochberger, L. (2021, January 12). Cybereason vs. Conti Ransomware. Retrieved February 17, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1021.002 SMB/Windows Admin Shares |
MalwareConti | Conti can spread via SMB and encrypts files on different hosts, potentially compromising an entire network. |
| T1027 Obfuscated Files or Information |
MalwareConti | Conti can use compiler-based obfuscation for its code, encrypt DLLs, and hide Windows API calls. |
| T1055.001 Dynamic-link Library Injection |
MalwareConti | Conti has loaded an encrypted DLL into memory and then executes it. |
| T1080 Taint Shared Content |
MalwareConti | Conti can spread itself by infecting other remote machines via network shared drives. |
| T1106 Native API |
MalwareConti | Conti has used API calls during execution. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareConti | Conti has decrypted its payload using a hardcoded AES-256 key. |
| T1486 Data Encrypted for Impact |
MalwareConti | Conti can use |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.