Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
Ryuk has called |
| T1021.002 SMB/Windows Admin Shares |
Ryuk has used the C$ network share for lateral movement. |
| T1027 Obfuscated Files or Information |
Ryuk can use anti-disassembly and code transformation obfuscation techniques. |
| T1036 Masquerading |
Ryuk can create .dll files that actually contain a Rich Text File format document. |
| T1036.005 Match Legitimate Resource Name or Location |
Ryuk has constructed legitimate appearing installation folder paths by calling |
| T1053.005 Scheduled Task |
Ryuk can remotely create a scheduled task to execute itself on a system. |
| T1055 Process Injection |
Ryuk has injected itself into remote processes to encrypt files using a combination of |
| T1057 Process Discovery |
Ryuk has called |
| T1059.003 Windows Command Shell |
Ryuk has used |
| T1078.002 Domain Accounts |
Ryuk can use stolen domain admin accounts to move laterally within a victim domain. |
| T1083 File and Directory Discovery |
Ryuk has enumerated files and folders on all mounted drives. |
| T1106 Native API |
Ryuk has used multiple native APIs including |
| T1134 Access Token Manipulation |
Ryuk has attempted to adjust its token privileges to have the |
| T1205 Traffic Signaling |
Ryuk has used Wake-on-Lan to power on turned off systems for lateral movement. |
| T1222.001 Windows Permissions |
Ryuk can launch |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.