ATT&CKReferencesMandiant_UNC2165

Mandiant_UNC2165

Mandiant Intelligence. (2022, June 2). To HADES and Back: UNC2165 Shifts to LOCKBIT to Evade Sanctions. Retrieved July 29, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples18

TechniqueUsed byProcedure example
T1012
Query Registry
GroupIndrik Spider

Indrik Spider has used a service account to extract copies of the `Security` Registry hive.

T1021.001
Remote Desktop Protocol
GroupIndrik Spider

Indrik Spider has used RDP for lateral movement.

T1021.004
SSH
GroupIndrik Spider

Indrik Spider has used SSH for lateral movement.

T1059.003
Windows Command Shell
GroupIndrik Spider

Indrik Spider has used batch scripts on victim's machines.

T1078
Valid Accounts
GroupIndrik Spider

Indrik Spider has used valid accounts for initial access and lateral movement. Indrik Spider has also maintained access to the victim environment through the VPN infrastructure.

T1105
Ingress Tool Transfer
GroupIndrik Spider

Indrik Spider has downloaded additional scripts, malware, and tools onto a compromised host.

T1112
Modify Registry
GroupIndrik Spider

Indrik Spider has modified registry keys to prepare for ransomware execution and to disable common administrative utilities.

T1136.001
Local Account
GroupIndrik Spider

Indrik Spider has created local system accounts and has added the accounts to privileged groups.

T1484.001
Group Policy Modification
GroupIndrik Spider

Indrik Spider has used Group Policy Objects to deploy batch scripts.

T1486
Data Encrypted for Impact
GroupIndrik Spider

Indrik Spider has encrypted domain-controlled systems using BitPaymer. Additionally, Indrik Spider used PsExec to execute a ransomware script.

T1552.001
Credentials In Files
GroupIndrik Spider

Indrik Spider has searched files to obtain and exfiltrate credentials.

T1555.005
Password Managers
GroupIndrik Spider

Indrik Spider has accessed and exported passwords from password managers.

T1558.003
Kerberoasting
GroupIndrik Spider

Indrik Spider has conducted Kerberoasting attacks using a module from GitHub.

T1567.002
Exfiltration to Cloud Storage
GroupIndrik Spider

Indrik Spider has exfiltrated data using Rclone or MEGASync prior to deploying ransomware.

T1583
Acquire Infrastructure
GroupIndrik Spider

Indrik Spider has purchased access to victim VPNs to facilitate access to victim environments.

T1590
Gather Victim Network Information
GroupIndrik Spider

Indrik Spider has downloaded tools, such as the Advanced Port Scanner utility and Lansweeper, to conduct internal reconnaissance of the victim network. Indrik Spider has also accessed the victim’s VMware VCenter, which had information about host configuration, clusters, etc.

T1685
Disable or Modify Tools
GroupIndrik Spider

Indrik Spider used PsExec to leverage Windows Defender to disable scanning of all downloaded files and to restrict real-time monitoring. Indrik Spider has used `MpCmdRun` to revert the definitions in Microsoft Defender. Additionally, Indrik Spider has used WMI to stop or uninstall and reset anti-virus products and other defensive services.

T1685.005
Clear Windows Event Logs
GroupIndrik Spider

Indrik Spider has used Cobalt Strike to empty log files. Additionally, Indrik Spider has cleared all event logs using `wevutil`.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.