ATT&CKReferencesSophos Netwalker May 2020

Sophos Netwalker May 2020

Szappanos, G., Brandt, A.. (2020, May 27). Netwalker ransomware tools give insight into threat actor. Retrieved May 27, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1027.010
Command Obfuscation
MalwareNetwalker

Netwalker's PowerShell script has been obfuscated with multiple layers including base64 and hexadecimal encoding and XOR-encryption, as well as obfuscated PowerShell functions and variables.

T1059.001
PowerShell
MalwareNetwalker

Netwalker has been written in PowerShell and executed directly in memory, avoiding detection.

T1059.003
Windows Command Shell
MalwareNetwalker

Operators deploying Netwalker have used batch scripts to retrieve the Netwalker payload.

T1105
Ingress Tool Transfer
MalwareNetwalker

Operators deploying Netwalker have used psexec and certutil to retrieve the Netwalker payload.

T1140
Deobfuscate/Decode Files or Information
MalwareNetwalker

Netwalker's PowerShell script can decode and decrypt multiple layers of obfuscation, leading to the Netwalker DLL being loaded into memory.

T1490
Inhibit System Recovery
MalwareNetwalker

Netwalker can delete the infected system's Shadow Volumes to prevent recovery.

T1569.002
Service Execution
MalwareNetwalker

Operators deploying Netwalker have used psexec and certutil to retrieve the Netwalker payload.

T1570
Lateral Tool Transfer
MalwareNetwalker

Operators deploying Netwalker have used psexec to copy the Netwalker payload across accessible systems.

T1685
Disable or Modify Tools
MalwareNetwalker

Netwalker can detect and terminate active security software-related processes on infected systems.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.