ATT&CKSoftwareDEATHRANSOM

DEATHRANSOM

S0616

Malware.View on attack.mitre.org

About this malware

DEATHRANSOM is ransomware written in C that has been used since at least 2020, and has potential overlap with FIVEHANDS and HELLOKITTY.

Techniques used9

Procedure examples9

TechniqueProcedure example
T1047
Windows Management Instrumentation

DEATHRANSOM has the ability to use WMI to delete volume shadow copies.

T1071.001
Web Protocols

DEATHRANSOM can use HTTPS to download files.

T1083
File and Directory Discovery

DEATHRANSOM can use loop operations to enumerate directories on a compromised host.

T1105
Ingress Tool Transfer

DEATHRANSOM can download files to a compromised host.

T1135
Network Share Discovery

DEATHRANSOM has the ability to use loop operations to enumerate network resources.

T1486
Data Encrypted for Impact

DEATHRANSOM can use public and private key pair encryption to encrypt files for ransom payment.

T1490
Inhibit System Recovery

DEATHRANSOM can delete volume shadow copies on compromised hosts.

T1614.001
System Language Discovery

Some versions of DEATHRANSOM have performed language ID and keyboard layout checks; if either of these matched Russian, Kazakh, Belarusian, Ukrainian or Tatar DEATHRANSOM would exit.

T1680
Local Storage Discovery

DEATHRANSOM can enumerate logical drives on a target system.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. FireEye FiveHands April 2021 Open source
    McLellan, T. and Moore, J. et al. (2021, April 29). UNC2447 SOMBRAT and FIVEHANDS Ransomware: A Sophisticated Financial Threat. Retrieved June 2, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.