ATT&CKReferencesWired Lockergoga 2019

Wired Lockergoga 2019

Greenberg, A. (2019, March 25). A Guide to LockerGoga, the Ransomware Crippling Industrial Firms. Retrieved July 17, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples4

TechniqueUsed byProcedure example
T1486
Data Encrypted for Impact
MalwareLockerGoga

LockerGoga has encrypted files, including core Windows OS files, using RSA-OAEP MGF1 and then demanded Bitcoin be paid for the decryption key.

T1529
System Shutdown/Reboot
MalwareLockerGoga

LockerGoga has been observed shutting down infected systems.

T1553.002
Code Signing
MalwareLockerGoga

LockerGoga has been signed with stolen certificates in order to make it look more legitimate.

T1685
Disable or Modify Tools
MalwareLockerGoga

LockerGoga installation has been immediately preceded by a "task kill" command in order to disable anti-virus.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.