Brandt, Andrew. (2022, July 14). BlackCat ransomware attacks not merely a byproduct of bad luck. Retrieved December 20, 2022.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1134 Access Token Manipulation |
MalwareBlackCat | BlackCat has the ability modify access tokens. |
| T1135 Network Share Discovery |
MalwareBlackCat | BlackCat has the ability to discover network shares on compromised networks. |
| T1489 Service Stop |
MalwareBlackCat | BlackCat has the ability to stop VM services on compromised networks. |
| T1491.001 Internal Defacement |
MalwareBlackCat | BlackCat can change the desktop wallpaper on compromised hosts. |
| T1561.001 Disk Content Wipe |
MalwareBlackCat | BlackCat has the ability to wipe VM snapshots on compromised networks. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.