Data Encrypted for Impact

T1486

Technique.View on attack.mitre.org

About this technique

Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.

In the case of ransomware, it is typical that common user files like Office documents, PDFs, images, videos, audio, text, and source code files will be encrypted (and often renamed and/or tagged with specific file markers). Adversaries may need to first employ other behaviors, such as File and Directory Permissions Modification or System Shutdown/Reboot, in order to unlock and/or gain access to manipulate these files. In some cases, adversaries may encrypt critical system files, disk partitions, and the MBR. Adversaries may also encrypt virtual machines hosted on ESXi or other hypervisors.

To maximize impact on the target organization, malware designed for encrypting data may have worm-like features to propagate across a network by leveraging other attack techniques like Valid Accounts, OS Credential Dumping, and SMB/Windows Admin Shares. Encryption malware may also leverage Internal Defacement, such as changing victim wallpapers or ESXi server login messages, or otherwise intimidate victims by sending ransom notes or other messages to connected printers (known as "print bombing").

In cloud environments, storage objects within compromised accounts may also be encrypted. For example, in AWS environments, adversaries may leverage services such as AWS’s Server-Side Encryption with Customer Provided Keys (SSE-C) to encrypt data.

Detection rules21

Rules on DetectionCode tagged with T1486.

Sigma11

RuleLevelLog source
Antivirus - Ransomware SignaturecriticalNULL / antivirus
AWS KMS Imported Key Material Usagehighaws / NULL
Load Of RstrtMgr.DLL By A Suspicious Processhighwindows / image_load
Renamed Gpg.EXE Executionhighwindows / process_creation
Suspicious Creation TXT File in User Desktophighwindows / file_event
Suspicious Reg Add BitLockerhighwindows / process_creation
AWS EC2 Disable EBS Encryptionmediumaws / NULL
Microsoft 365 - Potential Ransomware Activitymediumm365 / NULL
Portable Gpg.EXE Executionmediumwindows / process_creation
Suspicious Appended Extensionmediumwindows / file_rename
Load Of RstrtMgr.DLL By An Uncommon Processlowwindows / image_load

Splunk10

RuleTypeRiskData source
ASL AWS Detect Users creating keys with encrypt policy without MFATTPNULLASL AWS CloudTrail
AWS Detect Users creating keys with encrypt policy without MFATTPNULLAWS CloudTrail CreateKey, AWS CloudTrail PutKeyPolicy
AWS Detect Users with KMS keys performing encryption S3AnomalyNULLAWS CloudTrail
High Process Termination FrequencyAnomalyNULLSysmon EventID 5
Ransomware Notes bulk creationAnomalyNULLSysmon EventID 11
Ryuk Test Files DetectedTTPNULLSysmon EventID 11
Samsam Test File WriteTTPNULLSysmon EventID 11
Windows .Key File Creation in Root DirectoryAnomalyNULLSysmon EventID 11
Windows BitLocker Suspicious Command UsageTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows DiskCryptor UsageHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups19

Software62

Show 38 more

Campaigns4

Procedure examples85

Groups19

Used byProcedure example
GroupAkira

Akira encrypts files in victim environments as part of ransomware operations.

GroupAPT38

APT38 has used Hermes ransomware to encrypt files with AES256.

GroupAPT41

APT41 used a ransomware called Encryptor RaaS to encrypt files on the targeted systems and provide a ransom note to the user. APT41 also used Microsoft Bitlocker to encrypt workstations and Jetico’s BestCrypt to encrypt servers.

GroupBlackByte

BlackByte has encrypted victim files for ransom. Early versions of BlackByte ransomware used a common key for encryption, but later versions use unique keys per victim.

GroupFIN7

FIN7 has encrypted virtual disk volumes on ESXi servers using a version of Darkside ransomware. Additionally, FIN7 has deployed ransomware as the end payload during big game hunting.

GroupFIN8

FIN8 has deployed ransomware such as Ragnar Locker, White Rabbit, and attempted to execute Noberus on compromised networks.

GroupINC Ransom

INC Ransom has used INC Ransomware to encrypt victim's data.

GroupIndrik Spider

Indrik Spider has encrypted domain-controlled systems using BitPaymer. Additionally, Indrik Spider used PsExec to execute a ransomware script.

View all 19 groups examples

Software62

Used byProcedure example
MalwareAkira

Akira can encrypt victim filesystems for financial extortion purposes including through the use of the ChaCha20 and ChaCha8 stream ciphers.

MalwareAkira _v2

The Akira _v2 encryptor targets the `/vmfs/volumes/` path by default and can use the rust-crypto 0.2.36 library crate for the encryption processes.

MalwareApostle

Apostle creates new, encrypted versions of files then deletes the originals, with the new filenames consisting of a random GUID and ".lock" for an extension.

MalwareAvaddon

Avaddon encrypts the victim system using a combination of AES256 and RSA encryption schemes.

MalwareAvosLocker

AvosLocker has encrypted files and network resources using AES-256 and added an `.avos`, `.avos2`, or `.AvosLinux` extension to filenames.

MalwareBabuk

Babuk can use ChaCha8 and ECDH to encrypt data.

MalwareBad Rabbit

Bad Rabbit has encrypted files and disks using AES-128-CBC and RSA-2048.

MalwareBitPaymer

BitPaymer can import a hard-coded RSA 1024-bit public key, generate a 128-bit RC4 key for each file, and encrypt the file in place, appending .locked to the filename.

View all 62 software examples

Campaigns4

Used byProcedure example
CampaignC0015

During C0015, the threat actors used Conti ransomware to encrypt a compromised network.

CampaignC0018

During C0018, the threat actors used AvosLocker ransomware to encrypt files on the compromised network.

CampaignHomeLand Justice

During HomeLand Justice, threat actors used ROADSWEEP ransomware to encrypt files on targeted systems.

CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors deployed ransomware including 4L4MD4R and Warlock.

References10

  1. CarbonBlack Conti July 2020 Open source
    Baskin, B. (2020, July 8). TAU Threat Discovery: Conti Ransomware. Retrieved February 17, 2021.
  2. Crowdstrike Hypervisor Jackpotting Pt 2 2021 Open source
    Michael Dawson. (2021, August 30). Hypervisor Jackpotting, Part 2: eCrime Actors Increase Targeting of ESXi Servers with Ransomware. Retrieved March 26, 2025.
  3. FireEye WannaCry 2017 Open source
    Berry, A., Homan, J., and Eitzman, R. (2017, May 23). WannaCry Malware Profile. Retrieved March 15, 2019.
  4. Halcyon AWS Ransomware 2025 Open source
    Halcyon RISE Team. (2025, January 13). Abusing AWS Native Services: Ransomware Encrypting S3 Buckets with SSE-C. Retrieved March 18, 2025.
  5. NHS Digital Egregor Nov 2020 Open source
    NHS Digital. (2020, November 26). Egregor Ransomware The RaaS successor to Maze. Retrieved December 29, 2020.
  6. Rhino S3 Ransomware Part 1 Open source
    Gietzen, S. (n.d.). S3 Ransomware Part 1: Attack Vector. Retrieved April 14, 2021.
  7. US-CERT NotPetya 2017 Open source
    US-CERT. (2017, July 1). Alert (TA17-181A): Petya Ransomware. Retrieved March 15, 2019.
  8. US-CERT Ransomware 2016 Open source
    US-CERT. (2016, March 31). Alert (TA16-091A): Ransomware and Recent Variants. Retrieved March 15, 2019.
  9. US-CERT SamSam 2018 Open source
    US-CERT. (2018, December 3). Alert (AA18-337A): SamSam Ransomware. Retrieved March 15, 2019.
  10. Varonis Open source
    Jason Hill. (2023, February 8). VMware ESXi in the Line of Ransomware Fire. Retrieved March 26, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.