T1486 Data Encrypted for Impact — ATT&CK Technique
Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted. In the case of ransomware, it is typical that common user files like Office documents, PDFs, images, videos, audio, text, and source code files will be encrypted (and often renamed and/or tagged with specific file markers). Adversaries may need to first employ other behaviors, such as File and Directory Permissions Modification or System Shutdown/Reboot, in order to unlock and/or gain access to manipulate these files. In some cases, adversaries may encrypt critical system files, disk partitions, and the MBR. Adversaries may also encrypt virtual machines hosted on ESXi or other hypervisors. To maximize impact on the target organization, malware designed for encrypting data may have worm-like features to propagate across a network by leveraging other attack techniques like Valid Accounts, OS Credential Dumping, and SMB/Windows Admin Shares. Encryption malware may also leverage Internal Defacement, such as changing victim wallpapers or ESXi server login messages, or otherwise intimidate victims by sending ransom notes or other messages to connected printers (known as "print bombing"). In cloud environments, storage objects within compromised accounts may also be encrypted. For example, in AWS environments, adversaries may leverage services such as AWS’s Server-Side Encryption with Customer Provided Keys (SSE-C) to encrypt data.
Detection coverage (26)
- WannaCry Ransomware Activity critical
- LockerGoga Ransomware Activity critical
- Potential Conti Ransomware Activity critical
- BlueSky Ransomware Artefacts high
- FunkLocker Ransomware File Creation high
- Suspicious Creation TXT File in User Desktop medium
- AWS EC2 Disable EBS Encryption medium
- Antivirus Ransomware Detection critical
- AWS KMS Imported Key Material Usage high
- Microsoft 365 - Potential Ransomware Activity medium
- Suspicious Reg Add BitLocker high
- Load Of RstrtMgr.DLL By A Suspicious Process high
- Suspicious Appended Extension medium
- Load Of RstrtMgr.DLL By An Uncommon Process low
- Portable Gpg.EXE Execution medium
- Renamed Gpg.EXE Execution high
- ASL AWS Detect Users creating keys with encrypt policy without MFA
- AWS Detect Users creating keys with encrypt policy without MFA
- AWS Detect Users with KMS keys performing encryption S3
- High Process Termination Frequency
- Ransomware Notes bulk creation
- Ryuk Test Files Detected
- Samsam Test File Write
- Windows .Key File Creation in Root Directory
- Windows BitLocker Suspicious Command Usage
- Windows DiskCryptor Usage
Malware using this technique
- Maze
- Bad Rabbit
- ThiefQuest
- Ragnar Locker
- BlackByte Ransomware
- Royal
- JCry
- Babuk
- Moneybird
- LODEINFO
- REvil
- Diavol
- Cuba
- Playcrypt
- DarkGate
- BlackCat
- Prestige
- LockerGoga
- DEATHRANSOM
- EKANS
- ProLock
- AvosLocker
- HELLOKITTY
- BitPaymer
- Cheerscrypt
- BlackByte 2.0 Ransomware
- WannaCry
- ROADSWEEP
- DCSrv
- Black Basta
- WastedLocker
- Pysa
- ShrinkLocker
- INC Ransomware
- Qilin
- MegaCortex
- SynAck
- Akira _v2
- FIVEHANDS
- Conti
- Xbash
- Pay2Key
- RansomHub
- Egregor
- NotPetya
- SamSam
- Ryuk
- Shamoon
- Avaddon
- Netwalker