ATT&CKReferencesClearSky Pay2Kitten December 2020

ClearSky Pay2Kitten December 2020

ClearSky. (2020, December 17). Pay2Key Ransomware – A New Campaign by Fox Kitten. Retrieved December 21, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples14

TechniqueUsed byProcedure example
T1021.001
Remote Desktop Protocol
GroupFox Kitten

Fox Kitten has used RDP to log in and move laterally in the target environment.

T1046
Network Service Discovery
GroupFox Kitten

Fox Kitten has used tools including NMAP to conduct broad scanning to identify open ports.

T1053.005
Scheduled Task
GroupFox Kitten

Fox Kitten has used Scheduled Tasks for persistence and to load and execute a reverse proxy binary.

T1059
Command and Scripting Interpreter
GroupFox Kitten

Fox Kitten has used a Perl reverse shell to communicate with C2.

T1090
Proxy
GroupFox Kitten

Fox Kitten has used the open source reverse proxy tools including FRPC and Go Proxy to establish connections from C2 to local servers.

T1102
Web Service
GroupFox Kitten

Fox Kitten has used Amazon Web Services to host C2.

T1110
Brute Force
GroupFox Kitten

Fox Kitten has brute forced RDP credentials.

T1136.001
Local Account
GroupFox Kitten

Fox Kitten has created a local user account with administrator privileges.

T1190
Exploit Public-Facing Application
GroupFox Kitten

Fox Kitten has exploited known vulnerabilities in Fortinet, PulseSecure, and Palo Alto VPN appliances.

T1210
Exploitation of Remote Services
GroupFox Kitten

Fox Kitten has exploited known vulnerabilities in remote services including RDP.

T1505.003
Web Shell
GroupFox Kitten

Fox Kitten has installed web shells on compromised hosts to maintain access.

T1572
Protocol Tunneling
GroupFox Kitten

Fox Kitten has used protocol tunneling for communication and RDP activity on compromised hosts through the use of open source tools such as ngrok and custom tool SSHMinion.

T1585
Establish Accounts
GroupFox Kitten

Fox Kitten has created KeyBase accounts to communicate with ransomware victims.

T1585.001
Social Media Accounts
GroupFox Kitten

Fox Kitten has used a Twitter account to communicate with ransomware victims.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.