ATT&CKReferencesCheck Point Pay2Key November 2020

Check Point Pay2Key November 2020

Check Point. (2020, November 6). Ransomware Alert: Pay2Key. Retrieved January 4, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwarePay2Key

Pay2Key can identify the IP and MAC addresses of the compromised host.

T1070.004
File Deletion
MalwarePay2Key

Pay2Key can remove its log file from disk.

T1082
System Information Discovery
MalwarePay2Key

Pay2Key has the ability to gather the hostname of the victim machine.

T1090
Proxy
GroupFox Kitten

Fox Kitten has used the open source reverse proxy tools including FRPC and Go Proxy to establish connections from C2 to local servers.

T1090.001
Internal Proxy
MalwarePay2Key

Pay2Key has designated machines in the compromised network to serve as reverse proxy pivot points to channel communications with C2.

T1095
Non-Application Layer Protocol
MalwarePay2Key

Pay2Key has sent its public key to the C2 server over TCP.

T1486
Data Encrypted for Impact
MalwarePay2Key

Pay2Key can encrypt data on victim's machines using RSA and AES algorithms in order to extort a ransom payment for decryption.

T1489
Service Stop
MalwarePay2Key

Pay2Key can stop the MS SQL service at the end of the encryption process to release files locked by the service.

T1573.002
Asymmetric Cryptography
MalwarePay2Key

Pay2Key has used RSA encrypted communications with C2.

T1585
Establish Accounts
GroupFox Kitten

Fox Kitten has created KeyBase accounts to communicate with ransomware victims.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.