Venere, G. Neal, C. (2022, June 21). Avos ransomware group expands with new attack arsenal. Retrieved January 11, 2023.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.010 Command Obfuscation |
CampaignC0018 | During C0018, the threat actors used Base64 to encode their PowerShell scripts. |
| T1036 Masquerading |
CampaignC0018 | During C0018, AvosLocker was disguised using the victim company name as the filename. |
| T1036.005 Match Legitimate Resource Name or Location |
CampaignC0018 | For C0018, the threat actors renamed a Sliver payload to `vmware_kb.exe`. |
| T1046 Network Service Discovery |
CampaignC0018 | During C0018, the threat actors used the SoftPerfect Network Scanner for network scanning. |
| T1047 Windows Management Instrumentation |
CampaignC0018 | During C0018, the threat actors used WMIC to modify administrative settings on both a local and a remote host, likely as part of the first stages for their lateral movement; they also used WMI Provider Host (`wmiprvse.exe`) to execute a variety of encoded PowerShell scripts using the `DownloadString` method. |
| T1059.001 PowerShell |
CampaignC0018 | During C0018, the threat actors used encoded PowerShell scripts for execution. |
| T1072 Software Deployment Tools |
CampaignC0018 | During C0018, the threat actors used PDQ Deploy to move AvosLocker and tools across the network. |
| T1105 Ingress Tool Transfer |
CampaignC0018 | During C0018, the threat actors downloaded additional tools, such as Mimikatz and Sliver, as well as Cobalt Strike and AvosLocker ransomware onto the victim network. |
| T1190 Exploit Public-Facing Application |
CampaignC0018 | During C0018, the threat actors exploited VMWare Horizon Unified Access Gateways that were vulnerable to several Log4Shell vulnerabilities, including CVE-2021-44228, CVE-2021-45046, CVE-2021-45105, and CVE-2021-44832. |
| T1219.002 Remote Desktop Software |
CampaignC0018 | During C0018, the threat actors used AnyDesk to transfer tools between systems. |
| T1486 Data Encrypted for Impact |
MalwareAvosLocker | AvosLocker has encrypted files and network resources using AES-256 and added an `.avos`, `.avos2`, or `.AvosLinux` extension to filenames. |
| T1486 Data Encrypted for Impact |
CampaignC0018 | During C0018, the threat actors used AvosLocker ransomware to encrypt files on the compromised network. |
| T1570 Lateral Tool Transfer |
CampaignC0018 | During C0018, the threat actors transferred the SoftPerfect Network Scanner and other tools to machines in the network using AnyDesk and PDQ Deploy. |
| T1588.002 Tool |
CampaignC0018 | For C0018, the threat actors acquired a variety of open source tools, including Mimikatz, Sliver, SoftPerfect Network Scanner, AnyDesk, and PDQ Deploy. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.