ATT&CKReferencesTrendMicro Netwalker May 2020

TrendMicro Netwalker May 2020

Victor, K.. (2020, May 18). Netwalker Fileless Ransomware Injected via Reflective Loading . Retrieved May 26, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples13

TechniqueUsed byProcedure example
T1027.009
Embedded Payloads
MalwareNetwalker

Netwalker's DLL has been embedded within the PowerShell script in hex format.

T1027.010
Command Obfuscation
MalwareNetwalker

Netwalker's PowerShell script has been obfuscated with multiple layers including base64 and hexadecimal encoding and XOR-encryption, as well as obfuscated PowerShell functions and variables.

T1047
Windows Management Instrumentation
MalwareNetwalker

Netwalker can use WMI to delete Shadow Volumes.

T1055.001
Dynamic-link Library Injection
MalwareNetwalker

The Netwalker DLL has been injected reflectively into the memory of a legitimate running process.

T1059.001
PowerShell
MalwareNetwalker

Netwalker has been written in PowerShell and executed directly in memory, avoiding detection.

T1082
System Information Discovery
MalwareNetwalker

Netwalker can determine the system architecture it is running on to choose which version of the DLL to use.

T1106
Native API
MalwareNetwalker

Netwalker can use Windows API functions to inject the ransomware DLL.

T1112
Modify Registry
MalwareNetwalker

Netwalker can add the following registry entry: HKEY_CURRENT_USER\SOFTWARE\{8 random characters}.

T1486
Data Encrypted for Impact
MalwareNetwalker

Netwalker can encrypt files on infected machines to extort victims.

T1489
Service Stop
MalwareNetwalker

Netwalker can terminate system processes and services, some of which relate to backup software.

T1490
Inhibit System Recovery
MalwareNetwalker

Netwalker can delete the infected system's Shadow Volumes to prevent recovery.

T1518.001
Security Software Discovery
MalwareNetwalker

Netwalker can detect and terminate active security software-related processes on infected systems.

T1685
Disable or Modify Tools
MalwareNetwalker

Netwalker can detect and terminate active security software-related processes on infected systems.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.