Kimberly Goody, Jeremy Kennelly, Joshua Shilko, Steve Elovitz, Douglas Bienstock. (2020, October 28). Unhappy Hour Special: KEGTAP and SINGLEMALT With a Ransomware Chaser. Retrieved October 28, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.002 Security Account Manager |
GroupWizard Spider | Wizard Spider has acquired credentials from the SAM/SECURITY registry hives. |
| T1003.003 NTDS |
GroupWizard Spider | Wizard Spider has gained access to credentials via exported copies of the ntds.dit Active Directory database. Wizard Spider has also created a volume shadow copy and used a batch script file to collect NTDS.dit with the use of the Windows utility, ntdsutil. |
| T1018 Remote System Discovery |
GroupWizard Spider | Wizard Spider has used networkdll for network discovery and psfin specifically for financial and point of sale indicators. Wizard Spider has also used AdFind, |
| T1036.004 Masquerade Task or Service |
GroupWizard Spider | Wizard Spider has used scheduled tasks to install TrickBot, using task names to appear legitimate such as WinDotNet, GoogleTask, or Sysnetsf. It has also used common document file names for other malware binaries. |
| T1047 Windows Management Instrumentation |
GroupWizard Spider | Wizard Spider has used WMI and LDAP queries for network discovery and to move laterally. Wizard Spider has also used batch scripts to leverage WMIC to deploy ransomware. |
| T1053.005 Scheduled Task |
GroupWizard Spider | Wizard Spider has used scheduled tasks to establish persistence for TrickBot and other malware. |
| T1059.001 PowerShell |
GroupWizard Spider | Wizard Spider has used macros to execute PowerShell scripts to download malware on victim's machines. It has also used PowerShell to execute commands and move laterally through a victim network. |
| T1078.002 Domain Accounts |
GroupWizard Spider | Wizard Spider has used administrative accounts, including Domain Admin, to move laterally within a victim network. |
| T1133 External Remote Services |
GroupWizard Spider | Wizard Spider has accessed victim networks by using stolen credentials to access the corporate VPN infrastructure. |
| T1210 Exploitation of Remote Services |
GroupWizard Spider | Wizard Spider has exploited or attempted to exploit Zerologon (CVE-2020-1472) and EternalBlue (MS17-010) vulnerabilities. |
| T1547.001 Registry Run Keys / Startup Folder |
GroupWizard Spider | Wizard Spider has established persistence via the Registry key |
| T1547.004 Winlogon Helper DLL |
GroupWizard Spider | Wizard Spider has established persistence using Userinit by adding the Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon. |
| T1557.001 Name Resolution Poisoning and SMB Relay |
GroupWizard Spider | Wizard Spider has used the Invoke-Inveigh PowerShell cmdlets, likely for name service poisoning. |
| T1558.003 Kerberoasting |
GroupWizard Spider | Wizard Spider has used Rubeus, MimiKatz Kerberos module, and the Invoke-Kerberoast cmdlet to steal AES hashes. |
| T1588.002 Tool |
GroupWizard Spider | Wizard Spider has utilized tools such as Empire, Cobalt Strike, Cobalt Strike, Rubeus, AdFind, BloodHound, Metasploit, Advanced IP Scanner, Nirsoft PingInfoView, and SoftPerfect Network Scanner for targeting efforts. |
| T1685 Disable or Modify Tools |
GroupWizard Spider | Wizard Spider has shut down or uninstalled security applications on victim systems that might prevent ransomware from executing. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.