Amitai Ben & Shushan Ehrlich. (2021, May). From Wiper to Ransomware: The Evolution of Agrius. Retrieved May 21, 2024.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareIPsec Helper | IPsec Helper can identify specific files and folders for follow-on exfiltration. |
| T1021.001 Remote Desktop Protocol |
GroupAgrius | Agrius tunnels RDP traffic through deployed web shells to access victim environments via compromised accounts. Agrius used the Plink tool to tunnel RDP connections for remote access and lateral movement in victim environments. |
| T1027.009 Embedded Payloads |
MalwareDEADWOOD | DEADWOOD contains an embedded, AES-encrypted payload labeled |
| T1027.013 Encrypted/Encoded File |
MalwareDEADWOOD | DEADWOOD contains an embedded, AES-encrypted resource named |
| T1027.013 Encrypted/Encoded File |
MalwareIPsec Helper | IPsec Helper contains an embedded XML configuration file with an encrypted list of command and control servers. These are written to an external configuration file during execution. |
| T1036.004 Masquerade Task or Service |
MalwareDEADWOOD | DEADWOOD will attempt to masquerade its service execution using benign-looking names such as |
| T1041 Exfiltration Over C2 Channel |
MalwareIPsec Helper | IPsec Helper exfiltrates specific files through its command and control framework. |
| T1053.005 Scheduled Task |
MalwareApostle | Apostle achieves persistence by creating a scheduled task, such as |
| T1057 Process Discovery |
MalwareIPsec Helper | IPsec Helper can identify the process it is currently running under and its number, and pass this back to a command and control node. |
| T1057 Process Discovery |
MalwareApostle | Apostle retrieves a list of all running processes on a victim host, and stops all services containing the string "sql," likely to propagate ransomware activity to database files. |
| T1059.001 PowerShell |
MalwareIPsec Helper | IPsec Helper can run arbitrary PowerShell commands passed to it. |
| T1059.003 Windows Command Shell |
GroupAgrius | Agrius uses ASPXSpy web shells to enable follow-on command execution via |
| T1059.003 Windows Command Shell |
MalwareIPsec Helper | IPsec Helper can run arbitrary commands passed to it through |
| T1059.005 Visual Basic |
MalwareIPsec Helper | IPsec Helper can run arbitrary Visual Basic scripts and commands passed to it. |
| T1070 Indicator Removal |
MalwareIPsec Helper | IPsec Helper can delete various registry keys related to its execution and use. |
| T1070.004 File Deletion |
MalwareApostle | Apostle writes batch scripts to disk, such as |
| T1070.004 File Deletion |
MalwareIPsec Helper | IPsec Helper can delete itself when given the appropriate command. |
| T1070.009 Clear Persistence |
MalwareIPsec Helper | IPsec Helper can delete various service traces related to persistent execution when commanded. |
| T1071.001 Web Protocols |
MalwareIPsec Helper | IPsec Helper connects to command and control servers via HTTP POST requests based on parameters hard-coded into the malware. |
| T1112 Modify Registry |
MalwareIPsec Helper | IPsec Helper can make arbitrary changes to registry keys based on provided input. |
| T1124 System Time Discovery |
MalwareDEADWOOD | DEADWOOD will set a timestamp value to determine when wiping functionality starts. When the timestamp is met on the system, a trigger file is created on the operating system allowing for execution to proceed. If the timestamp is in the past, the wiper will execute immediately. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareDEADWOOD | DEADWOOD XORs some strings within the binary using the value |
| T1140 Deobfuscate/Decode Files or Information |
MalwareApostle | Apostle compiled code is obfuscated in an unspecified fashion prior to delivery to victims. |
| T1140 Deobfuscate/Decode Files or Information |
GroupAgrius | Agrius has deployed base64-encoded variants of ASPXSpy to evade detection. |
| T1190 Exploit Public-Facing Application |
GroupAgrius | Agrius exploits public-facing applications for initial access to victim environments. Examples include widespread attempts to exploit CVE-2018-13379 in FortiOS devices and SQL injection activity. |
| T1480 Execution Guardrails |
MalwareApostle | Apostle's ransomware variant requires that a base64-encoded argument is passed when executed, that is used as the Public Key for subsequent encryption operations. If Apostle is executed without this argument, it automatically runs a self-delete function. |
| T1485 Data Destruction |
MalwareDEADWOOD | DEADWOOD overwrites files on victim systems with random data to effectively destroy them. |
| T1485 Data Destruction |
MalwareApostle | Apostle initially masqueraded as ransomware but actual functionality is a data destruction tool, supported by an internal name linked to an early version, |
| T1486 Data Encrypted for Impact |
MalwareApostle | Apostle creates new, encrypted versions of files then deletes the originals, with the new filenames consisting of a random GUID and ".lock" for an extension. |
| T1497.003 Time Based Checks |
MalwareIPsec Helper | IPsec Helper will sleep for a random number of seconds, iterating 200 times over sleeps between one to three seconds, before continuing execution flow. |
| T1505.003 Web Shell |
GroupAgrius | Agrius typically deploys a variant of the ASPXSpy web shell following initial access via exploitation. |
| T1529 System Shutdown/Reboot |
MalwareApostle | Apostle reboots the victim machine following wiping and related activity. |
| T1531 Account Access Removal |
MalwareDEADWOOD | DEADWOOD changes the password for local and domain users via |
| T1543.003 Windows Service |
GroupAgrius | Agrius has deployed IPsec Helper malware post-exploitation and registered it as a service for persistence. |
| T1561.001 Disk Content Wipe |
MalwareApostle | Apostle searches for files on available drives based on a list of extensions hard-coded into the sample for follow-on wipe activity. |
| T1561.001 Disk Content Wipe |
MalwareDEADWOOD | DEADWOOD deletes files following overwriting them with random data. |
| T1561.002 Disk Structure Wipe |
MalwareDEADWOOD | DEADWOOD opens and writes zeroes to the first 512 bytes of each drive, deleting the MBR. DEADWOOD then sends the control code |
| T1569.002 Service Execution |
MalwareDEADWOOD | DEADWOOD can be executed as a service using various names, such as |
| T1569.002 Service Execution |
MalwareIPsec Helper | IPsec Helper is run as a Windows service in victim environments. |
| T1570 Lateral Tool Transfer |
MalwareIPsec Helper | IPsec Helper can download additional payloads from command and control nodes and execute them. |
| T1583 Acquire Infrastructure |
GroupAgrius | Agrius typically uses commercial VPN services for anonymizing last-hop traffic to victim networks, such as ProtonVPN. |
| T1685.005 Clear Windows Event Logs |
MalwareApostle | Apostle will attempt to delete all event logs on a victim machine following file wipe activity. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.