Malware.View on attack.mitre.org
FIVEHANDS is a customized version of DEATHRANSOM ransomware written in C++. FIVEHANDS has been used since at least 2021, including in Ransomware-as-a-Service (RaaS) campaigns, sometimes along with SombRAT.
| Technique | Procedure example |
|---|---|
| T1027.013 Encrypted/Encoded File |
The FIVEHANDS payload is encrypted with AES-128. |
| T1047 Windows Management Instrumentation |
FIVEHANDS can use WMI to delete files on a target machine. |
| T1059 Command and Scripting Interpreter |
FIVEHANDS can receive a command line argument to limit file encryption to specified directories. |
| T1083 File and Directory Discovery |
FIVEHANDS has the ability to enumerate files on a compromised host in order to encrypt files with specific extensions. |
| T1135 Network Share Discovery |
FIVEHANDS can enumerate network shares and mounted drives on a network. |
| T1140 Deobfuscate/Decode Files or Information |
FIVEHANDS has the ability to decrypt its payload prior to execution. |
| T1486 Data Encrypted for Impact |
FIVEHANDS can use an embedded NTRU public key to encrypt data for ransom. |
| T1490 Inhibit System Recovery |
FIVEHANDS has the ability to delete volume shadow copies on compromised hosts. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.