Check Point. (2020, November 6). Ransomware Alert: Pay2Key. Retrieved January 4, 2021.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1016 System Network Configuration Discovery |
MalwarePay2Key | Pay2Key can identify the IP and MAC addresses of the compromised host. |
| T1070.004 File Deletion |
MalwarePay2Key | Pay2Key can remove its log file from disk. |
| T1082 System Information Discovery |
MalwarePay2Key | Pay2Key has the ability to gather the hostname of the victim machine. |
| T1090 Proxy |
GroupFox Kitten | Fox Kitten has used the open source reverse proxy tools including FRPC and Go Proxy to establish connections from C2 to local servers. |
| T1090.001 Internal Proxy |
MalwarePay2Key | Pay2Key has designated machines in the compromised network to serve as reverse proxy pivot points to channel communications with C2. |
| T1095 Non-Application Layer Protocol |
MalwarePay2Key | Pay2Key has sent its public key to the C2 server over TCP. |
| T1486 Data Encrypted for Impact |
MalwarePay2Key | Pay2Key can encrypt data on victim's machines using RSA and AES algorithms in order to extort a ransom payment for decryption. |
| T1489 Service Stop |
MalwarePay2Key | Pay2Key can stop the MS SQL service at the end of the encryption process to release files locked by the service. |
| T1573.002 Asymmetric Cryptography |
MalwarePay2Key | Pay2Key has used RSA encrypted communications with C2. |
| T1585 Establish Accounts |
GroupFox Kitten | Fox Kitten has created KeyBase accounts to communicate with ransomware victims. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.