Malware.View on attack.mitre.org
DEATHRANSOM is ransomware written in C that has been used since at least 2020, and has potential overlap with FIVEHANDS and HELLOKITTY.
| Technique | Procedure example |
|---|---|
| T1047 Windows Management Instrumentation |
DEATHRANSOM has the ability to use WMI to delete volume shadow copies. |
| T1071.001 Web Protocols |
DEATHRANSOM can use HTTPS to download files. |
| T1083 File and Directory Discovery |
DEATHRANSOM can use loop operations to enumerate directories on a compromised host. |
| T1105 Ingress Tool Transfer |
DEATHRANSOM can download files to a compromised host. |
| T1135 Network Share Discovery |
DEATHRANSOM has the ability to use loop operations to enumerate network resources. |
| T1486 Data Encrypted for Impact |
DEATHRANSOM can use public and private key pair encryption to encrypt files for ransom payment. |
| T1490 Inhibit System Recovery |
DEATHRANSOM can delete volume shadow copies on compromised hosts. |
| T1614.001 System Language Discovery |
Some versions of DEATHRANSOM have performed language ID and keyboard layout checks; if either of these matched Russian, Kazakh, Belarusian, Ukrainian or Tatar DEATHRANSOM would exit. |
| T1680 Local Storage Discovery |
DEATHRANSOM can enumerate logical drives on a target system. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.