ATT&CKReferencesRed Canary Hospital Thwarted Ryuk October 2020

Red Canary Hospital Thwarted Ryuk October 2020

Brian Donohue, Katie Nickels, Paul Michaud, Adina Bodkins, Taylor Chapman, Tony Lambert, Jeff Felling, Kyle Rainey, Mike Haag, Matt Graeber, Aaron Didier.. (2020, October 29). A Bazar start: How one hospital thwarted a Ryuk ransomware outbreak. Retrieved October 30, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
ToolAdFind

AdFind can extract subnet information from Active Directory.

T1018
Remote System Discovery
ToolAdFind

AdFind has the ability to query Active Directory for computers.

T1018
Remote System Discovery
GroupWizard Spider

Wizard Spider has used networkdll for network discovery and psfin specifically for financial and point of sale indicators. Wizard Spider has also used AdFind, nltest/dclist, and PowerShell script Get-DataInfo.ps1 to enumerate domain computers, including the domain controller.

T1047
Windows Management Instrumentation
GroupWizard Spider

Wizard Spider has used WMI and LDAP queries for network discovery and to move laterally. Wizard Spider has also used batch scripts to leverage WMIC to deploy ransomware.

T1059.001
PowerShell
GroupWizard Spider

Wizard Spider has used macros to execute PowerShell scripts to download malware on victim's machines. It has also used PowerShell to execute commands and move laterally through a victim network.

T1069.002
Domain Groups
ToolAdFind

AdFind can enumerate domain groups.

T1087.002
Domain Account
ToolAdFind

AdFind can enumerate domain users.

T1482
Domain Trust Discovery
ToolAdFind

AdFind can gather information about organizational units (OUs) and domain trusts from Active Directory.

T1566.001
Spearphishing Attachment
GroupWizard Spider

Wizard Spider has used spearphishing attachments to deliver Microsoft documents containing macros or PDFs containing malicious links to download either Emotet, Bokbot, TrickBot, or Bazar.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.