Internal Defacement

T1491.001

Sub-technique of T1491 Defacement.View on attack.mitre.org

About this technique

An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems. This may take the form of modifications to internal websites or server login messages, or directly to user systems with the replacement of the desktop wallpaper. Disturbing or offensive images may be used as a part of Internal Defacement in order to cause user discomfort, or to pressure compliance with accompanying messages. Since internally defacing systems exposes an adversary's presence, it often takes place after other intrusion goals have been accomplished.

Detection rules4

Rules on DetectionCode tagged with T1491.001.

Sigma4

Splunk0

No Splunk rules are mapped to this technique yet.

Groups4

Software11

Campaigns0

None recorded.

Procedure examples15

Groups4

Used byProcedure example
GroupBlackByte

BlackByte left ransom notes in all directories where encryption takes place.

GroupGamaredon Group

Gamaredon Group has left taunting images and messages on the victims' desktops as proof of system access.

GroupLazarus Group

Lazarus Group replaced the background wallpaper of systems with a threatening image after rendering the system unbootable with a Disk Structure Wipe.

GroupShinyHunters

ShinyHunters has left ransom notes titled README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT.

Software11

Used byProcedure example
MalwareBlack Basta

Black Basta has set the desktop wallpaper on victims' machines to display a ransom note.

MalwareBlackCat

BlackCat can change the desktop wallpaper on compromised hosts.

MalwareDiavol

After encryption, Diavol will capture the desktop background window, set the background color to black, and change the desktop wallpaper to a newly created bitmap image with the text “All your files are encrypted! For more information see “README-FOR-DECRYPT.txt".

MalwareINC Ransomware

INC Ransomware has the ability to change the background wallpaper image to display the ransom note.

MalwareMeteor

Meteor can change both the desktop wallpaper and the lock screen image to a custom image.

MalwareQilin

Qilin can set the wallpaper on compromised hosts to display a ransom message in each encrypted folder.

MalwareRansomHub

RansomHub has placed a ransom note on comrpomised systems to warn victims and provide directions for how to retrieve data.

ToolRemcos

Remcos has the ability to modify the desktop wallpaper.

View all 11 software examples

References3

  1. Novetta Blockbuster Open source
    Novetta Threat Research Group. (2016, February 24). Operation Blockbuster: Unraveling the Long Thread of the Sony Attack. Retrieved February 25, 2016.
  2. Novetta Blockbuster Destructive Malware Open source
    Novetta Threat Research Group. (2016, February 24). Operation Blockbuster: Destructive Malware Report. Retrieved November 17, 2024.
  3. Varonis Open source
    Jason Hill. (2023, February 8). VMware ESXi in the Line of Ransomware Fire. Retrieved March 26, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.