Sub-technique of T1491 Defacement.View on attack.mitre.org
An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems. This may take the form of modifications to internal websites or server login messages, or directly to user systems with the replacement of the desktop wallpaper. Disturbing or offensive images may be used as a part of Internal Defacement in order to cause user discomfort, or to pressure compliance with accompanying messages. Since internally defacing systems exposes an adversary's presence, it often takes place after other intrusion goals have been accomplished.
Rules on DetectionCode tagged with T1491.001.
| Rule | Level | Log source |
|---|---|---|
| Potential Ransomware Activity Using LegalNotice Message | high | windows / registry_set |
| Potentially Suspicious Desktop Background Change Using Reg.EXE | medium | windows / process_creation |
| Potentially Suspicious Desktop Background Change Via Registry | medium | windows / registry_set |
| Replace Desktop Wallpaper by Powershell | low | windows / ps_script |
None recorded.
| Used by | Procedure example |
|---|---|
| GroupBlackByte | BlackByte left ransom notes in all directories where encryption takes place. |
| GroupGamaredon Group | Gamaredon Group has left taunting images and messages on the victims' desktops as proof of system access. |
| GroupLazarus Group | Lazarus Group replaced the background wallpaper of systems with a threatening image after rendering the system unbootable with a Disk Structure Wipe. |
| GroupShinyHunters | ShinyHunters has left ransom notes titled README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT. |
| Used by | Procedure example |
|---|---|
| MalwareBlack Basta | Black Basta has set the desktop wallpaper on victims' machines to display a ransom note. |
| MalwareBlackCat | BlackCat can change the desktop wallpaper on compromised hosts. |
| MalwareDiavol | After encryption, Diavol will capture the desktop background window, set the background color to black, and change the desktop wallpaper to a newly created bitmap image with the text “All your files are encrypted! For more information see “README-FOR-DECRYPT.txt". |
| MalwareINC Ransomware | INC Ransomware has the ability to change the background wallpaper image to display the ransom note. |
| MalwareMeteor | Meteor can change both the desktop wallpaper and the lock screen image to a custom image. |
| MalwareQilin | Qilin can set the wallpaper on compromised hosts to display a ransom message in each encrypted folder. |
| MalwareRansomHub | RansomHub has placed a ransom note on comrpomised systems to warn victims and provide directions for how to retrieve data. |
| ToolRemcos | Remcos has the ability to modify the desktop wallpaper. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.