DCSrv

S1033

Malware.View on attack.mitre.org

About this malware

DCSrv is destructive malware that has been used by Moses Staff since at least September 2021. Though DCSrv has ransomware-like capabilities, Moses Staff does not demand ransom or offer a decryption key.

Techniques used8

Procedure examples8

TechniqueProcedure example
T1027.013
Encrypted/Encoded File

DCSrv's configuration is encrypted.

T1036.004
Masquerade Task or Service

DCSrv has masqueraded its service as a legitimate svchost.exe process.

T1106
Native API

DCSrv has used various Windows API functions, including `DeviceIoControl`, as part of its encryption process.

T1112
Modify Registry

DCSrv has created Registry keys for persistence.

T1124
System Time Discovery

DCSrv can compare the current time on an infected host with a configuration value to determine when to start the encryption process.

T1486
Data Encrypted for Impact

DCSrv has encrypted drives using the core encryption mechanism from DiskCryptor.

T1529
System Shutdown/Reboot

DCSrv has a function to sleep for two hours before rebooting the system.

T1543.003
Windows Service

DCSrv has created new services for persistence by modifying the Registry.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Checkpoint MosesStaff Nov 2021 Open source
    Checkpoint Research. (2021, November 15). Uncovering MosesStaff techniques: Ideology over Money. Retrieved August 11, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.