Malware.View on attack.mitre.org
REvil is a ransomware family that has been linked to the GOLD SOUTHFIELD group and operated as ransomware-as-a-service (RaaS) since at least April 2019. REvil, which as been used against organizations in the manufacturing, transportation, and electric sectors, is highly configurable and shares code similarities with the GandCrab RaaS.
| Technique | Procedure example |
|---|---|
| T1007 System Service Discovery |
REvil can enumerate active services. |
| T1012 Query Registry |
REvil can query the Registry to get random file extensions to append to encrypted files. |
| T1027.011 Fileless Storage |
REvil can save encryption parameters and system information in the Registry. |
| T1027.013 Encrypted/Encoded File |
REvil has used encrypted strings and configuration files. |
| T1036.005 Match Legitimate Resource Name or Location |
REvil can mimic the names of known executables. |
| T1041 Exfiltration Over C2 Channel |
REvil can exfiltrate host and malware information to C2 servers. |
| T1047 Windows Management Instrumentation |
REvil can use WMI to monitor for and kill specific processes listed in its configuration file. |
| T1055 Process Injection |
REvil can inject itself into running processes on a compromised host. |
| T1059.001 PowerShell |
REvil has used PowerShell to delete volume shadow copies and download files. |
| T1059.003 Windows Command Shell |
REvil can use the Windows command line to delete volume shadow copies and disable recovery. |
| T1059.005 Visual Basic |
REvil has used obfuscated VBA macros for execution. |
| T1069.002 Domain Groups |
REvil can identify the domain membership of a compromised host. |
| T1070.004 File Deletion |
REvil can mark its binary code for deletion after reboot. |
| T1071.001 Web Protocols |
REvil has used HTTP and HTTPS in communication with C2. |
| T1082 System Information Discovery |
REvil can identify the username, machine name, system language, keyboard layout, and OS version on a compromised host. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.