Sanmillan, I.. (2020, May 13). Ramsay: A cyber‑espionage toolkit tailored for air‑gapped networks. Retrieved May 27, 2020.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1005 Data from Local System |
MalwareRamsay | Ramsay can collect Microsoft Word documents from the target's file system, as well as |
| T1014 Rootkit |
MalwareRamsay | Ramsay has included a rootkit to evade defenses. |
| T1025 Data from Removable Media |
MalwareRamsay | Ramsay can collect data from removable media and stage it for exfiltration. |
| T1027 Obfuscated Files or Information |
MalwareRamsay | Ramsay has base64-encoded its portable executable and hidden itself under a JPG header. Ramsay can also embed information within document footers. |
| T1036 Masquerading |
MalwareRamsay | Ramsay has masqueraded as a JPG image file. |
| T1036.005 Match Legitimate Resource Name or Location |
MalwareRamsay | Ramsay has masqueraded as a 7zip installer. |
| T1039 Data from Network Shared Drive |
MalwareRamsay | Ramsay can collect data from network drives and stage it for exfiltration. |
| T1046 Network Service Discovery |
MalwareRamsay | Ramsay can scan for systems that are vulnerable to the EternalBlue exploit. |
| T1053.005 Scheduled Task |
MalwareRamsay | Ramsay can schedule tasks via the Windows COM API to maintain persistence. |
| T1055.001 Dynamic-link Library Injection |
MalwareRamsay | Ramsay can use |
| T1059.005 Visual Basic |
MalwareRamsay | Ramsay has included embedded Visual Basic scripts in malicious documents. |
| T1074.001 Local Data Staging |
MalwareRamsay | Ramsay can stage data prior to exfiltration in |
| T1080 Taint Shared Content |
MalwareRamsay | Ramsay can spread itself by infecting other portable executable files on networks shared drives. |
| T1083 File and Directory Discovery |
MalwareRamsay | Ramsay can collect directory and file lists. |
| T1091 Replication Through Removable Media |
MalwareRamsay | Ramsay can spread itself by infecting other portable executable files on removable drives. |
| T1106 Native API |
MalwareRamsay | Ramsay can use Windows API functions such as |
| T1119 Automated Collection |
MalwareRamsay | Ramsay can conduct an initial scan for Microsoft Word documents on the local system, removable media, and connected network drives, before tagging and collecting them. It can continue tagging documents to collect with follow up scans. |
| T1120 Peripheral Device Discovery |
MalwareRamsay | Ramsay can scan for removable media which may contain documents for collection. |
| T1135 Network Share Discovery |
MalwareRamsay | Ramsay can scan for network drives which may contain documents for collection. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareRamsay | Ramsay can extract its agent from the body of a malicious document. |
| T1203 Exploitation for Client Execution |
MalwareRamsay | Ramsay has been embedded in documents exploiting CVE-2017-0199, CVE-2017-11882, and CVE-2017-8570. |
| T1546.010 AppInit DLLs |
MalwareRamsay | Ramsay can insert itself into the address space of other applications using the AppInit DLL Registry key. |
| T1548.002 Bypass User Account Control |
MalwareRamsay | |
| T1559.001 Component Object Model |
MalwareRamsay | Ramsay can use the Windows COM API to schedule tasks and maintain persistence. |
| T1559.002 Dynamic Data Exchange |
MalwareRamsay | Ramsay has been delivered using OLE objects in malicious documents. |
| T1560.001 Archive via Utility |
MalwareRamsay | Ramsay can compress and archive collected files using WinRAR. |
| T1560.003 Archive via Custom Method |
MalwareRamsay | Ramsay can store collected documents in a custom container after encrypting and compressing them using RC4 and WinRAR. |
| T1574.001 DLL |
MalwareRamsay | Ramsay can hijack outdated Windows application dependencies with malicious versions of its own DLL payload. |
| T1680 Local Storage Discovery |
MalwareRamsay | Ramsay can detect system information--including disk names, total space, and remaining space--to create a hardware profile GUID which acts as a system identifier for operators. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.