ATT&CKReferencesCybereason Conti Jan 2021

Cybereason Conti Jan 2021

Rochberger, L. (2021, January 12). Cybereason vs. Conti Ransomware. Retrieved February 17, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1021.002
SMB/Windows Admin Shares
MalwareConti

Conti can spread via SMB and encrypts files on different hosts, potentially compromising an entire network.

T1027
Obfuscated Files or Information
MalwareConti

Conti can use compiler-based obfuscation for its code, encrypt DLLs, and hide Windows API calls.

T1055.001
Dynamic-link Library Injection
MalwareConti

Conti has loaded an encrypted DLL into memory and then executes it.

T1080
Taint Shared Content
MalwareConti

Conti can spread itself by infecting other remote machines via network shared drives.

T1106
Native API
MalwareConti

Conti has used API calls during execution.

T1140
Deobfuscate/Decode Files or Information
MalwareConti

Conti has decrypted its payload using a hardcoded AES-256 key.

T1486
Data Encrypted for Impact
MalwareConti

Conti can use CreateIoCompletionPort(), PostQueuedCompletionStatus(), and GetQueuedCompletionPort() to rapidly encrypt files, excluding those with the extensions of .exe, .dll, and .lnk. It has used a different AES-256 encryption key per file with a bundled RAS-4096 public encryption key that is unique for each victim. Conti can use “Windows Restart Manager” to ensure files are unlocked and open for encryption.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.