Szappanos, G., Brandt, A.. (2020, May 27). Netwalker ransomware tools give insight into threat actor. Retrieved May 27, 2020.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.010 Command Obfuscation |
MalwareNetwalker | Netwalker's PowerShell script has been obfuscated with multiple layers including base64 and hexadecimal encoding and XOR-encryption, as well as obfuscated PowerShell functions and variables. |
| T1059.001 PowerShell |
MalwareNetwalker | Netwalker has been written in PowerShell and executed directly in memory, avoiding detection. |
| T1059.003 Windows Command Shell |
MalwareNetwalker | Operators deploying Netwalker have used batch scripts to retrieve the Netwalker payload. |
| T1105 Ingress Tool Transfer |
MalwareNetwalker | Operators deploying Netwalker have used psexec and certutil to retrieve the Netwalker payload. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareNetwalker | Netwalker's PowerShell script can decode and decrypt multiple layers of obfuscation, leading to the Netwalker DLL being loaded into memory. |
| T1490 Inhibit System Recovery |
MalwareNetwalker | Netwalker can delete the infected system's Shadow Volumes to prevent recovery. |
| T1569.002 Service Execution |
MalwareNetwalker | Operators deploying Netwalker have used psexec and certutil to retrieve the Netwalker payload. |
| T1570 Lateral Tool Transfer |
MalwareNetwalker | Operators deploying Netwalker have used psexec to copy the Netwalker payload across accessible systems. |
| T1685 Disable or Modify Tools |
MalwareNetwalker | Netwalker can detect and terminate active security software-related processes on infected systems. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.