Microsoft Defender Threat Intelligence. (2022, June 13). The many lives of BlackCat ransomware. Retrieved December 20, 2022.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1018 Remote System Discovery |
MalwareBlackCat | BlackCat can broadcasts NetBIOS Name Service (NBNC) messages to search for servers connected to compromised networks. |
| T1033 System Owner/User Discovery |
MalwareBlackCat | BlackCat can utilize `net use` commands to discover the user name on a compromised host. |
| T1047 Windows Management Instrumentation |
MalwareBlackCat | BlackCat can use `wmic.exe` to delete shadow copies on compromised networks. |
| T1059.003 Windows Command Shell |
MalwareBlackCat | BlackCat can execute commands on a compromised network with the use of `cmd.exe`. |
| T1069.002 Domain Groups |
MalwareBlackCat | BlackCat can determine if a user on a compromised host has domain admin privileges. |
| T1082 System Information Discovery |
MalwareBlackCat | BlackCat can obtain the computer name and UUID. |
| T1083 File and Directory Discovery |
MalwareBlackCat | BlackCat can enumerate files for encryption. |
| T1087.002 Domain Account |
MalwareBlackCat | BlackCat can utilize `net use` commands to identify domain users. |
| T1112 Modify Registry |
MalwareBlackCat | BlackCat has the ability to add the following registry key on compromised networks to maintain persistence: `HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services \LanmanServer\Paramenters` |
| T1134 Access Token Manipulation |
MalwareBlackCat | BlackCat has the ability modify access tokens. |
| T1135 Network Share Discovery |
MalwareBlackCat | BlackCat has the ability to discover network shares on compromised networks. |
| T1222.001 Windows Permissions |
MalwareBlackCat | BlackCat can use Windows commands such as `fsutil behavior set SymLinkEvaluation R2L:1` to redirect file system access to a different location after gaining access into compromised networks. |
| T1486 Data Encrypted for Impact |
MalwareBlackCat | BlackCat has the ability to encrypt Windows devices, Linux devices, and VMWare instances. |
| T1489 Service Stop |
MalwareBlackCat | BlackCat has the ability to stop VM services on compromised networks. |
| T1490 Inhibit System Recovery |
MalwareBlackCat | BlackCat can delete shadow copies using `vssadmin.exe delete shadows /all /quiet` and `wmic.exe Shadowcopy Delete`; it can also modify the boot loader using `bcdedit /set {default} recoveryenabled No`. |
| T1491.001 Internal Defacement |
MalwareBlackCat | BlackCat can change the desktop wallpaper on compromised hosts. |
| T1548.002 Bypass User Account Control |
MalwareBlackCat | BlackCat can bypass UAC to escalate privileges. |
| T1561.001 Disk Content Wipe |
MalwareBlackCat | BlackCat has the ability to wipe VM snapshots on compromised networks. |
| T1570 Lateral Tool Transfer |
MalwareBlackCat | BlackCat can replicate itself across connected servers via `psexec`. |
| T1680 Local Storage Discovery |
MalwareBlackCat | BlackCat can enumerate local drives. |
| T1685.005 Clear Windows Event Logs |
MalwareBlackCat | BlackCat can clear Windows event logs using `wevtutil.exe`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.