ATT&CKReferencesTetra Defense Sodinokibi March 2020

Tetra Defense Sodinokibi March 2020

Tetra Defense. (2020, March). CAUSE AND EFFECT: SODINOKIBI RANSOMWARE ANALYSIS. Retrieved November 17, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples6

TechniqueUsed byProcedure example
T1027.010
Command Obfuscation
GroupGOLD SOUTHFIELD

GOLD SOUTHFIELD has executed base64 encoded PowerShell scripts on compromised hosts.

T1059.001
PowerShell
GroupGOLD SOUTHFIELD

GOLD SOUTHFIELD has staged and executed PowerShell scripts on compromised hosts.

T1113
Screen Capture
GroupGOLD SOUTHFIELD

GOLD SOUTHFIELD has used the remote monitoring and management tool ConnectWise to obtain screen captures from victim's machines.

T1219
Remote Access Tools
GroupGOLD SOUTHFIELD

GOLD SOUTHFIELD has used the cloud-based remote management and monitoring tool "ConnectWise Control" to deploy REvil.

T1486
Data Encrypted for Impact
MalwareREvil

REvil can encrypt files on victim systems and demands a ransom to decrypt the files.

T1490
Inhibit System Recovery
MalwareREvil

REvil can use vssadmin to delete volume shadow copies and bcdedit to disable recovery features.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.