ATT&CKReferencesSophos BlackCat Jul 2022

Sophos BlackCat Jul 2022

Brandt, Andrew. (2022, July 14). BlackCat ransomware attacks not merely a byproduct of bad luck. Retrieved December 20, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples5

TechniqueUsed byProcedure example
T1134
Access Token Manipulation
MalwareBlackCat

BlackCat has the ability modify access tokens.

T1135
Network Share Discovery
MalwareBlackCat

BlackCat has the ability to discover network shares on compromised networks.

T1489
Service Stop
MalwareBlackCat

BlackCat has the ability to stop VM services on compromised networks.

T1491.001
Internal Defacement
MalwareBlackCat

BlackCat can change the desktop wallpaper on compromised hosts.

T1561.001
Disk Content Wipe
MalwareBlackCat

BlackCat has the ability to wipe VM snapshots on compromised networks.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.