Greenberg, A. (2019, March 25). A Guide to LockerGoga, the Ransomware Crippling Industrial Firms. Retrieved July 17, 2019.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1486 Data Encrypted for Impact |
MalwareLockerGoga | LockerGoga has encrypted files, including core Windows OS files, using RSA-OAEP MGF1 and then demanded Bitcoin be paid for the decryption key. |
| T1529 System Shutdown/Reboot |
MalwareLockerGoga | LockerGoga has been observed shutting down infected systems. |
| T1553.002 Code Signing |
MalwareLockerGoga | LockerGoga has been signed with stolen certificates in order to make it look more legitimate. |
| T1685 Disable or Modify Tools |
MalwareLockerGoga | LockerGoga installation has been immediately preceded by a "task kill" command in order to disable anti-virus. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.