ATT&CKReferencesMicrosoft Ransomware as a Service

Microsoft Ransomware as a Service

Microsoft. (2022, May 9). Ransomware as a service: Understanding the cybercrime gig economy and how to protect yourself. Retrieved March 10, 2023.

Open the source

Techniques1

Groups2

Software1

Campaigns0

None recorded.

Procedure examples20

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
MalwareQakBot

QakBot can use net config workstation, arp -a, `nslookup`, and ipconfig /all to gather network configuration information.

T1047
Windows Management Instrumentation
GroupCinnamon Tempest

Cinnamon Tempest has used Impacket for lateral movement via WMI.

T1059.003
Windows Command Shell
GroupCinnamon Tempest

Cinnamon Tempest has executed ransomware using batch scripts deployed via GPO.

T1059.006
Python
GroupCinnamon Tempest

Cinnamon Tempest has used a customized version of the Impacket wmiexec.py module to create renamed output files.

T1078.002
Domain Accounts
GroupCinnamon Tempest

Cinnamon Tempest has obtained highly privileged credentials such as domain administrator in order to deploy malware.

T1078.003
Local Accounts
GroupFIN7

FIN7 has used compromised credentials for access as SYSTEM on Exchange servers.

T1080
Taint Shared Content
GroupCinnamon Tempest

Cinnamon Tempest has deployed ransomware from a batch file in a network share.

T1082
System Information Discovery
MalwareQakBot

QakBot can collect system information including the OS version and domain on a compromised host.

T1082
System Information Discovery
GroupMustard Tempest

Mustard Tempest has used implants to perform system reconnaissance on targeted systems.

T1105
Ingress Tool Transfer
GroupMustard Tempest

Mustard Tempest has deployed secondary payloads and third stage implants to compromised hosts.

T1190
Exploit Public-Facing Application
GroupCinnamon Tempest

Cinnamon Tempest has exploited multiple unpatched vulnerabilities for initial access including vulnerabilities in Microsoft Exchange, Manage Engine AdSelfService Plus, Confluence, and Log4j.

T1190
Exploit Public-Facing Application
GroupFIN7

FIN7 has compromised targeted organizations through exploitation of CVE-2021-31207 in Exchange.

T1204.001
Malicious Link
GroupMustard Tempest

Mustard Tempest has lured users into downloading malware through malicious links in fake advertisements and spearphishing emails.

T1204.002
Malicious File
MalwareQakBot

QakBot has gained execution through users opening malicious attachments.

T1484.001
Group Policy Modification
GroupCinnamon Tempest

Cinnamon Tempest has used Group Policy to deploy batch scripts for ransomware deployment.

T1566.001
Spearphishing Attachment
MalwareQakBot

QakBot has spread through emails with malicious attachments.

T1574.001
DLL
GroupCinnamon Tempest

Cinnamon Tempest has used search order hijacking to launch Cobalt Strike Beacons. Cinnamon Tempest has also abused legitimate executables to side-load weaponized DLLs.

T1583.008
Malvertising
GroupMustard Tempest

Mustard Tempest has posted false advertisements including for software packages and browser updates in order to distribute malware.

T1608.006
SEO Poisoning
GroupMustard Tempest

Mustard Tempest has poisoned search engine results to return fake software updates in order to distribute malware.

T1657
Financial Theft
GroupCinnamon Tempest

Cinnamon Tempest has maintained leak sites for exfiltrated data in attempt to extort victims into paying a ransom.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.