EKANS

S0605

Malware.View on attack.mitre.org

About this malware

EKANS is ransomware variant written in Golang that first appeared in mid-December 2019 and has been used against multiple sectors, including energy, healthcare, and automotive manufacturing, which in some cases resulted in significant operational disruptions. EKANS has used a hard-coded kill-list of processes, including some associated with common ICS software platforms (e.g., GE Proficy, Honeywell HMIWeb, etc), similar to those defined in MegaCortex.

Techniques used9

Procedure examples9

TechniqueProcedure example
T1016
System Network Configuration Discovery

EKANS can determine the domain of a compromised host.

T1027
Obfuscated Files or Information

EKANS uses encoded strings in its process kill list.

T1036.005
Match Legitimate Resource Name or Location

EKANS has been disguised as update.exe to appear as a valid executable.

T1047
Windows Management Instrumentation

EKANS can use Windows Mangement Instrumentation (WMI) calls to execute operations.

T1057
Process Discovery

EKANS looks for processes from a hard-coded list.

T1486
Data Encrypted for Impact

EKANS uses standard encryption library functions to encrypt files.

T1489
Service Stop

EKANS stops database, data backup solution, antivirus, and ICS-related processes.

T1490
Inhibit System Recovery

EKANS removes backups of Volume Shadow Copies to disable any restoration capabilities.

T1685
Disable or Modify Tools

EKANS stops processes related to security and management software.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References2

  1. Dragos EKANS Open source
    Dragos. (2020, February 3). EKANS Ransomware and ICS Operations. Retrieved February 9, 2021.
  2. Palo Alto Unit 42 EKANS Open source
    Hinchliffe, A. Santos, D. (2020, June 26). Threat Assessment: EKANS Ransomware. Retrieved February 9, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.