ATT&CKReferencesKaspersky Andariel Ransomware June 2021

Kaspersky Andariel Ransomware June 2021

Park, S. (2021, June 15). Andariel evolves to target South Korea with ransomware. Retrieved September 29, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples3

TechniqueUsed byProcedure example
T1027.003
Steganography
GroupAndariel

Andariel has hidden malicious executables within PNG files.

T1049
System Network Connections Discovery
GroupAndariel

Andariel has used the netstat -naop tcp command to display TCP connections on a victim's machine.

T1057
Process Discovery
GroupAndariel

Andariel has used tasklist to enumerate processes and find a specific string.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.