ATT&CKReferencesGroup IB Ransomware May 2020

Group IB Ransomware May 2020

Group IB. (2020, May). Ransomware Uncovered: Attackers’ Latest Methods. Retrieved August 5, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples5

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwareREvil

REvil has used encrypted strings and configuration files.

T1047
Windows Management Instrumentation
MalwareREvil

REvil can use WMI to monitor for and kill specific processes listed in its configuration file.

T1059.001
PowerShell
MalwareREvil

REvil has used PowerShell to delete volume shadow copies and download files.

T1082
System Information Discovery
MalwareREvil

REvil can identify the username, machine name, system language, keyboard layout, and OS version on a compromised host.

T1680
Local Storage Discovery
MalwareREvil

REvil can identify system drive information on a compromised host.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.