Vilkomir-Preisman, S. (2022, August 18). Beating Black Basta Ransomware. Retrieved March 8, 2023.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.006 HTML Smuggling |
MalwareQakBot | QakBot has been delivered in ZIP files via HTML smuggling. |
| T1059.003 Windows Command Shell |
MalwareBlack Basta | Black Basta can use `cmd.exe` to enable shadow copy deletion. |
| T1083 File and Directory Discovery |
MalwareBlack Basta | Black Basta can enumerate specific files for encryption. |
| T1112 Modify Registry |
MalwareBlack Basta | Black Basta has modified the Registry to enable itself to run in safe mode, to change the icons and file extensions for encrypted files, and to add the malware path for persistence. |
| T1204.002 Malicious File |
MalwareQakBot | QakBot has gained execution through users opening malicious attachments. |
| T1218.010 Regsvr32 |
MalwareQakBot | QakBot can use Regsvr32 to execute malicious DLLs. |
| T1480.002 Mutual Exclusion |
MalwareBlack Basta | Black Basta will check for the presence of a hard-coded mutex `dsajdhas.0` before executing. |
| T1486 Data Encrypted for Impact |
MalwareBlack Basta | Black Basta can encrypt files with the ChaCha20 cypher and using a multithreaded process to increase speed. Black Basta has also encrypted files while the victim system is in safe mode, appending `.basta` upon completion. BlackBerry Black Basta May 2022Check Point Black Basta October 2022Cyble Black Basta May 2022Deep Instinct Black Basta August 2022Minerva Labs Black Basta May 2022NCC Group Black Basta June 2022Palo Alto Networks Black Basta August 2022Trend Micro Black Basta May 2022Trend Micro Black Basta Spotlight September 2022Uptycs Black Basta ESXi June 2022 |
| T1490 Inhibit System Recovery |
MalwareBlack Basta | Black Basta can delete shadow copies using vssadmin.exe. Avertium Black Basta June 2022Check Point Black Basta October 2022Cyble Black Basta May 2022Deep Instinct Black Basta August 2022Minerva Labs Black Basta May 2022NCC Group Black Basta June 2022Palo Alto Networks Black Basta August 2022Trend Micro Black Basta May 2022Trend Micro Black Basta Spotlight September 2022 |
| T1491.001 Internal Defacement |
MalwareBlack Basta | Black Basta has set the desktop wallpaper on victims' machines to display a ransom note. |
| T1553.002 Code Signing |
MalwareQakBot | QakBot can use signed loaders to evade detection. |
| T1566.001 Spearphishing Attachment |
MalwareQakBot | QakBot has spread through emails with malicious attachments. |
| T1574.001 DLL |
MalwareQakBot | QakBot has the ability to use DLL side-loading for execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.