ATT&CKReferencesSophos New Ryuk Attack October 2020

Sophos New Ryuk Attack October 2020

Sean Gallagher, Peter Mackenzie, Elida Leite, Syed Shahram, Bill Kearney, Anand Aijan, Sivagnanam Gn, Suraj Mundalik. (2020, October 14). They’re back: inside a new Ryuk ransomware attack. Retrieved October 14, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples3

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
GroupWizard Spider

Wizard Spider has used ipconfig to identify the network configuration of a victim machine. Wizard Spider has also used the PowerShell cmdlet `Get-ADComputer` to collect IP address data from Active Directory.

T1033
System Owner/User Discovery
GroupWizard Spider

Wizard Spider has used "whoami" to identify the local user and their privileges.

T1222.001
Windows Permissions
GroupWizard Spider

Wizard Spider has used the icacls command to modify access control to backup servers, providing them with full control of all the system folders.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.