Malware.View on attack.mitre.org
Netwalker is fileless ransomware written in PowerShell and executed directly in memory.
| Technique | Procedure example |
|---|---|
| T1027.009 Embedded Payloads |
Netwalker's DLL has been embedded within the PowerShell script in hex format. |
| T1027.010 Command Obfuscation |
Netwalker's PowerShell script has been obfuscated with multiple layers including base64 and hexadecimal encoding and XOR-encryption, as well as obfuscated PowerShell functions and variables. |
| T1047 Windows Management Instrumentation |
Netwalker can use WMI to delete Shadow Volumes. |
| T1055.001 Dynamic-link Library Injection |
The Netwalker DLL has been injected reflectively into the memory of a legitimate running process. |
| T1059.001 PowerShell |
Netwalker has been written in PowerShell and executed directly in memory, avoiding detection. |
| T1059.003 Windows Command Shell |
Operators deploying Netwalker have used batch scripts to retrieve the Netwalker payload. |
| T1082 System Information Discovery |
Netwalker can determine the system architecture it is running on to choose which version of the DLL to use. |
| T1105 Ingress Tool Transfer |
Operators deploying Netwalker have used psexec and certutil to retrieve the Netwalker payload. |
| T1106 Native API |
Netwalker can use Windows API functions to inject the ransomware DLL. |
| T1112 Modify Registry |
Netwalker can add the following registry entry: |
| T1140 Deobfuscate/Decode Files or Information |
Netwalker's PowerShell script can decode and decrypt multiple layers of obfuscation, leading to the Netwalker DLL being loaded into memory. |
| T1486 Data Encrypted for Impact |
Netwalker can encrypt files on infected machines to extort victims. |
| T1489 Service Stop |
Netwalker can terminate system processes and services, some of which relate to backup software. |
| T1490 Inhibit System Recovery |
Netwalker can delete the infected system's Shadow Volumes to prevent recovery. |
| T1518.001 Security Software Discovery |
Netwalker can detect and terminate active security software-related processes on infected systems. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.