BlackCat

S1068

Malware.View on attack.mitre.org

About this malware

BlackCat is ransomware written in Rust that has been offered via the Ransomware-as-a-Service (RaaS) model. First observed November 2021, BlackCat has been used to target multiple sectors and organizations in various countries and regions in Africa, the Americas, Asia, Australia, and Europe.

Techniques used21

Procedure examples21

TechniqueProcedure example
T1018
Remote System Discovery

BlackCat can broadcasts NetBIOS Name Service (NBNC) messages to search for servers connected to compromised networks.

T1033
System Owner/User Discovery

BlackCat can utilize `net use` commands to discover the user name on a compromised host.

T1047
Windows Management Instrumentation

BlackCat can use `wmic.exe` to delete shadow copies on compromised networks.

T1059.003
Windows Command Shell

BlackCat can execute commands on a compromised network with the use of `cmd.exe`.

T1069.002
Domain Groups

BlackCat can determine if a user on a compromised host has domain admin privileges.

T1082
System Information Discovery

BlackCat can obtain the computer name and UUID.

T1083
File and Directory Discovery

BlackCat can enumerate files for encryption.

T1087.002
Domain Account

BlackCat can utilize `net use` commands to identify domain users.

T1112
Modify Registry

BlackCat has the ability to add the following registry key on compromised networks to maintain persistence: `HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services \LanmanServer\Paramenters`

T1134
Access Token Manipulation

BlackCat has the ability modify access tokens.

T1135
Network Share Discovery

BlackCat has the ability to discover network shares on compromised networks.

T1222.001
Windows Permissions

BlackCat can use Windows commands such as `fsutil behavior set SymLinkEvaluation R2L:1` to redirect file system access to a different location after gaining access into compromised networks.

T1486
Data Encrypted for Impact

BlackCat has the ability to encrypt Windows devices, Linux devices, and VMWare instances.

T1489
Service Stop

BlackCat has the ability to stop VM services on compromised networks.

T1490
Inhibit System Recovery

BlackCat can delete shadow copies using `vssadmin.exe delete shadows /all /quiet` and `wmic.exe Shadowcopy Delete`; it can also modify the boot loader using `bcdedit /set {default} recoveryenabled No`.

View all 21 procedure examples

Groups that use it1

Campaigns0

None recorded.

References3

  1. ACSC BlackCat Apr 2022 Open source
    Australian Cyber Security Centre. (2022, April 14). 2022-004: ACSC Ransomware Profile - ALPHV (aka BlackCat). Retrieved December 20, 2022.
  2. Microsoft BlackCat Jun 2022 Open source
    Microsoft Defender Threat Intelligence. (2022, June 13). The many lives of BlackCat ransomware. Retrieved December 20, 2022.
  3. Sophos BlackCat Jul 2022 Open source
    Brandt, Andrew. (2022, July 14). BlackCat ransomware attacks not merely a byproduct of bad luck. Retrieved December 20, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.