FIVEHANDS

S0618

Malware.View on attack.mitre.org

About this malware

FIVEHANDS is a customized version of DEATHRANSOM ransomware written in C++. FIVEHANDS has been used since at least 2021, including in Ransomware-as-a-Service (RaaS) campaigns, sometimes along with SombRAT.

Techniques used8

Procedure examples8

TechniqueProcedure example
T1027.013
Encrypted/Encoded File

The FIVEHANDS payload is encrypted with AES-128.

T1047
Windows Management Instrumentation

FIVEHANDS can use WMI to delete files on a target machine.

T1059
Command and Scripting Interpreter

FIVEHANDS can receive a command line argument to limit file encryption to specified directories.

T1083
File and Directory Discovery

FIVEHANDS has the ability to enumerate files on a compromised host in order to encrypt files with specific extensions.

T1135
Network Share Discovery

FIVEHANDS can enumerate network shares and mounted drives on a network.

T1140
Deobfuscate/Decode Files or Information

FIVEHANDS has the ability to decrypt its payload prior to execution.

T1486
Data Encrypted for Impact

FIVEHANDS can use an embedded NTRU public key to encrypt data for ransom.

T1490
Inhibit System Recovery

FIVEHANDS has the ability to delete volume shadow copies on compromised hosts.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References2

  1. FireEye FiveHands April 2021 Open source
    McLellan, T. and Moore, J. et al. (2021, April 29). UNC2447 SOMBRAT and FIVEHANDS Ransomware: A Sophisticated Financial Threat. Retrieved June 2, 2021.
  2. NCC Group Fivehands June 2021 Open source
    Matthews, M. and Backhouse, W. (2021, June 15). Handy guide to a new Fivehands ransomware variant. Retrieved June 24, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.