The DFIR Report. (2020, November 5). Ryuk Speed Run, 2 Hours to Ransom. Retrieved November 6, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1021.001 Remote Desktop Protocol |
GroupWizard Spider | Wizard Spider has used RDP for lateral movement and to deploy ransomware interactively. |
| T1021.002 SMB/Windows Admin Shares |
GroupWizard Spider | Wizard Spider has used SMB to drop Cobalt Strike Beacon on a domain controller for lateral movement. |
| T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol |
GroupWizard Spider | Wizard Spider has exfiltrated victim information using FTP. |
| T1053.005 Scheduled Task |
GroupWizard Spider | Wizard Spider has used scheduled tasks to establish persistence for TrickBot and other malware. |
| T1055.001 Dynamic-link Library Injection |
GroupWizard Spider | Wizard Spider has injected malicious DLLs into memory with read, write, and execute permissions. |
| T1482 Domain Trust Discovery |
ToolRubeus | Rubeus can gather information about domain trusts. |
| T1553.002 Code Signing |
GroupWizard Spider | Wizard Spider has used Digicert code-signing certificates for some of its malware. |
| T1558.003 Kerberoasting |
GroupWizard Spider | Wizard Spider has used Rubeus, MimiKatz Kerberos module, and the Invoke-Kerberoast cmdlet to steal AES hashes. |
| T1558.004 AS-REP Roasting |
ToolRubeus | Rubeus can reveal the credentials of accounts that have Kerberos pre-authentication disabled through AS-REP roasting. |
| T1566.002 Spearphishing Link |
GroupWizard Spider | Wizard Spider has sent phishing emails containing a link to an actor-controlled Google Drive document or other free online file hosting services. |
| T1588.003 Code Signing Certificates |
GroupWizard Spider | Wizard Spider has obtained code signing certificates signed by DigiCert, GlobalSign, and COMOOD for malware payloads. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.