ATT&CKReferencesMandiant FIN12 Oct 2021

Mandiant FIN12 Oct 2021

Shilko, J., et al. (2021, October 7). FIN12: The Prolific Ransomware Intrusion Threat Actor That Has Aggressively Pursued Healthcare Targets. Retrieved June 15, 2023.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples39

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupWizard Spider

Wizard Spider has dumped the lsass.exe memory to harvest credentials with the use of open-source tool LaZagne.

T1003.003
NTDS
GroupWizard Spider

Wizard Spider has gained access to credentials via exported copies of the ntds.dit Active Directory database. Wizard Spider has also created a volume shadow copy and used a batch script file to collect NTDS.dit with the use of the Windows utility, ntdsutil.

T1005
Data from Local System
GroupWizard Spider

Wizard Spider has collected data from a compromised host prior to exfiltration.

T1016
System Network Configuration Discovery
GroupWizard Spider

Wizard Spider has used ipconfig to identify the network configuration of a victim machine. Wizard Spider has also used the PowerShell cmdlet `Get-ADComputer` to collect IP address data from Active Directory.

T1018
Remote System Discovery
GroupWizard Spider

Wizard Spider has used networkdll for network discovery and psfin specifically for financial and point of sale indicators. Wizard Spider has also used AdFind, nltest/dclist, and PowerShell script Get-DataInfo.ps1 to enumerate domain computers, including the domain controller.

T1021
Remote Services
GroupWizard Spider

Wizard Spider has used the WebDAV protocol to execute Ryuk payloads hosted on network file shares.

T1021.001
Remote Desktop Protocol
GroupWizard Spider

Wizard Spider has used RDP for lateral movement and to deploy ransomware interactively.

T1041
Exfiltration Over C2 Channel
GroupWizard Spider

Wizard Spider has exfiltrated domain credentials and network enumeration information over command and control (C2) channels.

T1047
Windows Management Instrumentation
GroupWizard Spider

Wizard Spider has used WMI and LDAP queries for network discovery and to move laterally. Wizard Spider has also used batch scripts to leverage WMIC to deploy ransomware.

T1053.005
Scheduled Task
GroupWizard Spider

Wizard Spider has used scheduled tasks to establish persistence for TrickBot and other malware.

T1055
Process Injection
GroupWizard Spider

Wizard Spider has used process injection to execute payloads to escalate privileges.

T1059.001
PowerShell
GroupWizard Spider

Wizard Spider has used macros to execute PowerShell scripts to download malware on victim's machines. It has also used PowerShell to execute commands and move laterally through a victim network.

T1059.003
Windows Command Shell
GroupWizard Spider

Wizard Spider has used `cmd.exe` to execute commands on a victim's machine.

T1074.001
Local Data Staging
GroupWizard Spider

Wizard Spider has staged ZIP files in local directories such as, `C:\PerfLogs\1\` and `C:\User\1\` prior to exfiltration.

T1078
Valid Accounts
GroupWizard Spider

Wizard Spider has used valid credentials for privileged accounts with the goal of accessing domain controllers.

T1082
System Information Discovery
GroupWizard Spider

Wizard Spider has used Systeminfo and similar commands to acquire detailed configuration information of a victim's machine. Wizard Spider has also utilized the PowerShell cmdlet `Get-ADComputer` to collect DNS hostnames, last logon dates, and operating system information from Active Directory.

T1087.002
Domain Account
GroupWizard Spider

Wizard Spider has identified domain admins through the use of `net group "Domain admins" /DOMAIN`. Wizard Spider has also leveraged the PowerShell cmdlet `Get-ADComputer` to collect account names from Active Directory data.

T1105
Ingress Tool Transfer
GroupWizard Spider

Wizard Spider can transfer malicious payloads such as ransomware to compromised machines.

T1112
Modify Registry
GroupWizard Spider

Wizard Spider has modified the Registry key HKLM\System\CurrentControlSet\Control\SecurityProviders\WDigest by setting the UseLogonCredential registry value to 1 in order to force credentials to be stored in clear text in memory. Wizard Spider has also modified the WDigest registry key to allow plaintext credentials to be cached in memory.

T1136.001
Local Account
GroupWizard Spider

Wizard Spider has created local administrator accounts to maintain persistence in compromised networks.

T1136.002
Domain Account
GroupWizard Spider

Wizard Spider has created and used new accounts within a victim's Active Directory environment to maintain persistence.

T1197
BITS Jobs
GroupWizard Spider

Wizard Spider has used batch scripts that utilizes WMIC to execute a BITSAdmin transfer of a ransomware payload to each compromised machine.

T1204.002
Malicious File
GroupWizard Spider

Wizard Spider has lured victims to execute malware with spearphishing attachments containing macros to download either Emotet, Bokbot, TrickBot, or Bazar.

T1218.011
Rundll32
GroupWizard Spider

Wizard Spider has utilized `rundll32.exe` to deploy ransomware commands with the use of WebDAV.

T1490
Inhibit System Recovery
GroupWizard Spider

Wizard Spider has used WMIC and vssadmin to manually delete volume shadow copies. Wizard Spider has also used Conti ransomware to delete volume shadow copies automatically with the use of vssadmin.

T1518.002
Backup Software Discovery
GroupWizard Spider

Wizard Spider has utilized the PowerShell script `Get-DataInfo.ps1` to collect installed backup software information from a compromised machine.

T1543.003
Windows Service
GroupWizard Spider

Wizard Spider has installed TrickBot as a service named ControlServiceA in order to establish persistence.

T1550.002
Pass the Hash
GroupWizard Spider

Wizard Spider has used the `Invoke-SMBExec` PowerShell cmdlet to execute the pass-the-hash technique and utilized stolen password hashes to move laterally.

T1552.006
Group Policy Preferences
GroupWizard Spider

Wizard Spider has used PowerShell cmdlets `Get-GPPPassword` and `Find-GPOPassword` to find unsecured credentials in a compromised network group policy.

T1555.004
Windows Credential Manager
GroupWizard Spider

Wizard Spider has used PowerShell cmdlet `Invoke-WCMDump` to enumerate Windows credentials in the Credential Manager in a compromised network.

T1558.003
Kerberoasting
GroupWizard Spider

Wizard Spider has used Rubeus, MimiKatz Kerberos module, and the Invoke-Kerberoast cmdlet to steal AES hashes.

T1560.001
Archive via Utility
GroupWizard Spider

Wizard Spider has archived data into ZIP files on compromised machines.

T1566.001
Spearphishing Attachment
GroupWizard Spider

Wizard Spider has used spearphishing attachments to deliver Microsoft documents containing macros or PDFs containing malicious links to download either Emotet, Bokbot, TrickBot, or Bazar.

T1567.002
Exfiltration to Cloud Storage
GroupWizard Spider

Wizard Spider has exfiltrated stolen victim data to various cloud storage providers.

T1569.002
Service Execution
GroupWizard Spider

Wizard Spider has used `services.exe` to execute scripts and executables during lateral movement within a victim's network. Wizard Spider has also used batch scripts that leverage PsExec to execute a previously transferred ransomware payload on a victim's network.

T1585.002
Email Accounts
GroupWizard Spider

Wizard Spider has leveraged ProtonMail email addresses in ransom notes when delivering Ryuk ransomware.

T1588.002
Tool
GroupWizard Spider

Wizard Spider has utilized tools such as Empire, Cobalt Strike, Cobalt Strike, Rubeus, AdFind, BloodHound, Metasploit, Advanced IP Scanner, Nirsoft PingInfoView, and SoftPerfect Network Scanner for targeting efforts.

T1588.003
Code Signing Certificates
GroupWizard Spider

Wizard Spider has obtained code signing certificates signed by DigiCert, GlobalSign, and COMOOD for malware payloads.

T1685
Disable or Modify Tools
GroupWizard Spider

Wizard Spider has shut down or uninstalled security applications on victim systems that might prevent ransomware from executing.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.