ATT&CKReferencesFireEye Shining A Light on DARKSIDE May 2021

FireEye Shining A Light on DARKSIDE May 2021

FireEye. (2021, May 11). Shining a Light on DARKSIDE Ransomware Operations. Retrieved September 22, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples5

TechniqueUsed byProcedure example
T1056.001
Keylogging
MalwareSMOKEDHAM

SMOKEDHAM can continuously capture keystrokes.

T1102
Web Service
MalwareSMOKEDHAM

SMOKEDHAM has used Google Drive and Dropbox to host files downloaded by victims via malicious links.

T1113
Screen Capture
MalwareSMOKEDHAM

SMOKEDHAM can capture screenshots of the victim’s desktop.

T1204.001
Malicious Link
MalwareSMOKEDHAM

SMOKEDHAM has relied upon users clicking on a malicious link delivered through phishing.

T1598.003
Spearphishing Link
MalwareSMOKEDHAM

SMOKEDHAM has been delivered via malicious links in phishing emails.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.