Malware.View on attack.mitre.org
DCSrv is destructive malware that has been used by Moses Staff since at least September 2021. Though DCSrv has ransomware-like capabilities, Moses Staff does not demand ransom or offer a decryption key.
| Technique | Procedure example |
|---|---|
| T1027.013 Encrypted/Encoded File |
DCSrv's configuration is encrypted. |
| T1036.004 Masquerade Task or Service |
DCSrv has masqueraded its service as a legitimate svchost.exe process. |
| T1106 Native API |
DCSrv has used various Windows API functions, including `DeviceIoControl`, as part of its encryption process. |
| T1112 Modify Registry |
DCSrv has created Registry keys for persistence. |
| T1124 System Time Discovery |
DCSrv can compare the current time on an infected host with a configuration value to determine when to start the encryption process. |
| T1486 Data Encrypted for Impact |
DCSrv has encrypted drives using the core encryption mechanism from DiskCryptor. |
| T1529 System Shutdown/Reboot |
DCSrv has a function to sleep for two hours before rebooting the system. |
| T1543.003 Windows Service |
DCSrv has created new services for persistence by modifying the Registry. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.