ATT&CKReferencesDFIR Ryuk in 5 Hours October 2020

DFIR Ryuk in 5 Hours October 2020

The DFIR Report. (2020, October 18). Ryuk in 5 Hours. Retrieved October 19, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples2

TechniqueUsed byProcedure example
T1210
Exploitation of Remote Services
GroupWizard Spider

Wizard Spider has exploited or attempted to exploit Zerologon (CVE-2020-1472) and EternalBlue (MS17-010) vulnerabilities.

T1569.002
Service Execution
GroupWizard Spider

Wizard Spider has used `services.exe` to execute scripts and executables during lateral movement within a victim's network. Wizard Spider has also used batch scripts that leverage PsExec to execute a previously transferred ransomware payload on a victim's network.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.