ATT&CKReferencesFireEye Ryuk and Trickbot January 2019

FireEye Ryuk and Trickbot January 2019

Goody, K., et al (2019, January 11). A Nasty Trick: From Credential Theft Malware to Business Disruption. Retrieved May 12, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software2

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1016
System Network Configuration Discovery
ToolAdFind

AdFind can extract subnet information from Active Directory.

T1018
Remote System Discovery
ToolAdFind

AdFind has the ability to query Active Directory for computers.

T1018
Remote System Discovery
GroupWizard Spider

Wizard Spider has used networkdll for network discovery and psfin specifically for financial and point of sale indicators. Wizard Spider has also used AdFind, nltest/dclist, and PowerShell script Get-DataInfo.ps1 to enumerate domain computers, including the domain controller.

T1027.010
Command Obfuscation
GroupWizard Spider

Wizard Spider used Base64 encoding to obfuscate an Empire service and PowerShell commands.

T1069.002
Domain Groups
ToolAdFind

AdFind can enumerate domain groups.

T1087.002
Domain Account
ToolAdFind

AdFind can enumerate domain users.

T1482
Domain Trust Discovery
ToolAdFind

AdFind can gather information about organizational units (OUs) and domain trusts from Active Directory.

T1685
Disable or Modify Tools
MalwareRyuk

Ryuk has stopped services related to anti-virus.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.