ATT&CKReferencesNCC Group Fivehands June 2021

NCC Group Fivehands June 2021

Matthews, M. and Backhouse, W. (2021, June 15). Handy guide to a new Fivehands ransomware variant. Retrieved June 24, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwareFIVEHANDS

The FIVEHANDS payload is encrypted with AES-128.

T1059
Command and Scripting Interpreter
MalwareFIVEHANDS

FIVEHANDS can receive a command line argument to limit file encryption to specified directories.

T1083
File and Directory Discovery
MalwareFIVEHANDS

FIVEHANDS has the ability to enumerate files on a compromised host in order to encrypt files with specific extensions.

T1135
Network Share Discovery
MalwareFIVEHANDS

FIVEHANDS can enumerate network shares and mounted drives on a network.

T1136.002
Domain Account
ToolPsExec

PsExec has the ability to remotely create accounts on target systems.

T1140
Deobfuscate/Decode Files or Information
MalwareFIVEHANDS

FIVEHANDS has the ability to decrypt its payload prior to execution.

T1486
Data Encrypted for Impact
MalwareFIVEHANDS

FIVEHANDS can use an embedded NTRU public key to encrypt data for ransom.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.