Malware.View on attack.mitre.org
EKANS is ransomware variant written in Golang that first appeared in mid-December 2019 and has been used against multiple sectors, including energy, healthcare, and automotive manufacturing, which in some cases resulted in significant operational disruptions. EKANS has used a hard-coded kill-list of processes, including some associated with common ICS software platforms (e.g., GE Proficy, Honeywell HMIWeb, etc), similar to those defined in MegaCortex.
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
EKANS can determine the domain of a compromised host. |
| T1027 Obfuscated Files or Information |
EKANS uses encoded strings in its process kill list. |
| T1036.005 Match Legitimate Resource Name or Location |
EKANS has been disguised as |
| T1047 Windows Management Instrumentation |
EKANS can use Windows Mangement Instrumentation (WMI) calls to execute operations. |
| T1057 Process Discovery |
EKANS looks for processes from a hard-coded list. |
| T1486 Data Encrypted for Impact |
EKANS uses standard encryption library functions to encrypt files. |
| T1489 Service Stop |
EKANS stops database, data backup solution, antivirus, and ICS-related processes. |
| T1490 Inhibit System Recovery |
EKANS removes backups of Volume Shadow Copies to disable any restoration capabilities. |
| T1685 Disable or Modify Tools |
EKANS stops processes related to security and management software. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.