ATT&CKReferencesCarbon Black JCry May 2019

Carbon Black JCry May 2019

Lee, S.. (2019, May 14). JCry Ransomware. Retrieved June 18, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1059.001
PowerShell
MalwareJCry

JCry has used PowerShell to execute payloads.

T1059.003
Windows Command Shell
MalwareJCry

JCry has used cmd.exe to launch PowerShell.

T1059.005
Visual Basic
MalwareJCry

JCry has used VBS scripts.

T1204.002
Malicious File
MalwareJCry

JCry has achieved execution by luring users to click on a file that appeared to be an Adobe Flash Player update installer.

T1486
Data Encrypted for Impact
MalwareJCry

JCry has encrypted files and demanded Bitcoin to decrypt those files.

T1490
Inhibit System Recovery
MalwareJCry

JCry has been observed deleting shadow copies to ensure that data cannot be restored easily.

T1547.001
Registry Run Keys / Startup Folder
MalwareJCry

JCry has created payloads in the Startup directory to maintain persistence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.