Prestige

S1058

Malware.View on attack.mitre.org

About this malware

Prestige ransomware has been used by Sandworm Team since at least March 2022, including against transportation and related logistics industries in Ukraine and Poland in October 2022.

Techniques used9

Procedure examples9

TechniqueProcedure example
T1053.005
Scheduled Task

Prestige has been executed on a target system through a scheduled task created by Sandworm Team using Impacket.

T1059.001
PowerShell

Prestige can use PowerShell for payload execution on targeted systems.

T1083
File and Directory Discovery

Prestige can traverse the file system to discover files to encrypt by identifying specific extensions defined in a hardcoded list.

T1106
Native API

Prestige has used the `Wow64DisableWow64FsRedirection()` and `Wow64RevertWow64FsRedirection()` functions to disable and restore file system redirection.

T1112
Modify Registry

Prestige has the ability to register new registry keys for a new extension handler via `HKCR\.enc` and `HKCR\enc\shell\open\command`.

T1484.001
Group Policy Modification

Prestige has been deployed using the Default Domain Group Policy Object from an Active Directory Domain Controller.

T1486
Data Encrypted for Impact

Prestige has leveraged the CryptoPP C++ library to encrypt files on target systems using AES and appended filenames with `.enc`.

T1489
Service Stop

Prestige has attempted to stop the MSSQL Windows service to ensure successful encryption using `C:\Windows\System32\net.exe stop MSSQLSERVER`.

T1490
Inhibit System Recovery

Prestige can delete the backup catalog from the target system using: `c:\Windows\System32\wbadmin.exe delete catalog -quiet` and can also delete volume shadow copies using: `\Windows\System32\vssadmin.exe delete shadows /all /quiet`.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Microsoft Prestige ransomware October 2022 Open source
    MSTIC. (2022, October 14). New “Prestige” ransomware impacts organizations in Ukraine and Poland. Retrieved January 19, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.