ROADSWEEP

S1150

Malware.View on attack.mitre.org

About this malware

ROADSWEEP is a ransomware that was deployed against Albanian government networks during HomeLand Justice along with the CHIMNEYSWEEP backdoor.

Techniques used15

Procedure examples15

TechniqueProcedure example
T1027.013
Encrypted/Encoded File

The ROADSWEEP binary contains RC4 encrypted embedded scripts.

T1059.003
Windows Command Shell

ROADSWEEP can open cmd.exe to enable command execution.

T1070.004
File Deletion

ROADSWEEP can use embedded scripts to remove itself from the infected host.

T1083
File and Directory Discovery

ROADSWEEP can enumerate files on infected devices and avoid encrypting files with .exe, .dll, .sys, .lnk, or . lck extensions.

T1120
Peripheral Device Discovery

ROADSWEEP can identify removable drives attached to the victim's machine.

T1140
Deobfuscate/Decode Files or Information

ROADSWEEP can decrypt embedded scripts prior to execution.

T1480
Execution Guardrails

ROADSWEEP requires four command line arguments to execute correctly, otherwise it will produce a message box and halt execution.

T1486
Data Encrypted for Impact

ROADSWEEP can RC4 encrypt content in blocks on targeted systems.

T1489
Service Stop

ROADSWEEP can disable critical services and processes.

T1490
Inhibit System Recovery

ROADSWEEP has the ability to disable `SystemRestore` and Volume Shadow Copies.

T1491.001
Internal Defacement

ROADSWEEP has dropped ransom notes in targeted folders prior to encrypting the files.

T1547.001
Registry Run Keys / Startup Folder

ROADSWEEP has been placed in the start up folder to trigger execution upon user login.

T1553.002
Code Signing

ROADSWEEP has been digitally signed with a certificate issued to the Kuwait Telecommunications Company KSC.

T1559
Inter-Process Communication

ROADSWEEP can pipe command output to a targeted process.

T1680
Local Storage Discovery

ROADSWEEP can enumerate logical drives on targeted devices.

Groups that use it0

None recorded.

Campaigns1

References1

  1. Mandiant ROADSWEEP August 2022 Open source
    Jenkins, L. at al. (2022, August 4). ROADSWEEP Ransomware - Likely Iranian Threat Actor Conducts Politically Motivated Disruptive Activity Against Albanian Government Organizations. Retrieved August 6, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.