ATT&CKReferencesMcAfee REvil October 2019

McAfee REvil October 2019

Saavedra-Morales, J, et al. (2019, October 20). McAfee ATR Analyzes Sodinokibi aka REvil Ransomware-as-a-Service – Crescendo. Retrieved August 5, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples3

TechniqueUsed byProcedure example
T1055
Process Injection
MalwareREvil

REvil can inject itself into running processes on a compromised host.

T1204.002
Malicious File
MalwareREvil

REvil has been executed via malicious MS Word e-mail attachments.

T1486
Data Encrypted for Impact
MalwareREvil

REvil can encrypt files on victim systems and demands a ransom to decrypt the files.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.