Malware.View on attack.mitre.org
LockerGoga is ransomware that was first reported in January 2019, and has been tied to various attacks on European companies, including industrial and manufacturing firms.
| Technique | Procedure example |
|---|---|
| T1070.004 File Deletion |
LockerGoga has been observed deleting its original launcher after execution. |
| T1486 Data Encrypted for Impact |
LockerGoga has encrypted files, including core Windows OS files, using RSA-OAEP MGF1 and then demanded Bitcoin be paid for the decryption key. |
| T1529 System Shutdown/Reboot |
LockerGoga has been observed shutting down infected systems. |
| T1531 Account Access Removal |
LockerGoga has been observed changing account passwords and logging off current users. |
| T1553.002 Code Signing |
LockerGoga has been signed with stolen certificates in order to make it look more legitimate. |
| T1570 Lateral Tool Transfer |
LockerGoga has been observed moving around the victim network via SMB, indicating the actors behind this ransomware are manually copying files form computer to computer instead of self-propagating. |
| T1685 Disable or Modify Tools |
LockerGoga installation has been immediately preceded by a "task kill" command in order to disable anti-virus. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.