FORENSIA

ATT&CK · T1486

Data Encrypted for Impact

Tactics: impact

About

Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted. In the case of ransomware, it is typical that common user files like Office documents, PDFs, images, videos, audio, text, and source code files will be encrypted (and often renamed and/or tagged with specific file markers). Adversaries may need to first employ other behaviors, such as File and Directory Permissions Modification or System Shutdown/Reboot, in order to unlock and/or gain access to manipulate these files. In some cases, adversaries may encrypt critical system files, disk partitions, and the MBR. Adversaries may also encrypt virtual machines hosted on ESXi or other hypervisors. To maximize impact on the target organization, malware designed for encrypting data may have worm-like features to propagate across a network by leveraging other attack techniques like Valid Accounts, OS Credential Dumping, and SMB/Windows Admin Shares. Encryption malware may also leverage Internal Defacement, such as changing victim wallpapers or ESXi server login messages, or otherwise intimidate victims by sending ransom notes or other messages to connected printers (known as "print bombing"). In cloud environments, storage objects within compromised accounts may also be encrypted. For example, in AWS environments, adversaries may leverage services such as AWS’s Server-Side Encryption with Customer Provided Keys (SSE-C) to encrypt data.

Platforms: ESXi, IaaS, Linux, macOS, WindowsMITRE ATT&CK ↗

Used by actors

18 known groups

Software

62 malware/tools implement this

ShamoonSynAckXbashWannaCryNotPetyaSamSamLockerGogaJCryRobbinHoodRyukMazeNetwalkerRagnar LockerREvilEgregorPay2KeyBitPaymerContiMegaCortexPysaThiefQuestEKANSBad RabbitKillDiskClopWastedLockerDEATHRANSOMHELLOKITTYFIVEHANDSCubaBabukSeth-LockerAvaddonProLockXCSSETDiavolDCSrvAvosLockerPrestigeBlackCatBlack BastaRoyalCheerscryptDarkGateAkiraApostleMoneybirdINC RansomwareROADSWEEPPlaycryptShrinkLockerBlackByte RansomwareBlackByte 2.0 RansomwareMegazordAkira _v2LockBit 2.0LockBit 3.0RansomHubQilinMedusa RansomwareEmbargoLODEINFO

Corpus indicators tagged with this technique

656 indicators in the corpus carry T1486.

IndicatorTypeFamilySevSrc
cve-2025-34054cve854
cve-2021-27137cve858
cve-2025-1055cveransomware853
cve-2026-4368cveransomware851
cve-2016-15047cve854
cve-2025-61155cveransomware853
cve-2023-44976cveransomware852
cve-2023-52271cveransomware853
038cab0c60c53cf12f048272014024c0hashransomware802
2528df60e55f210a6396dd7740d76afe30d5e9e8684a5b8a02a63bdcb5041bfchashransomware802
0b1870d57221eec6f3bbef648e71a724hashransomware802
09d0517a1f69feff8186655ae3b567e0hashransomware802
16474e9e4773fbc1e0b48a5025fad31b7f084b1beffb9a42687b4d01979885fehashransomware802
28a9982cf2b4fc53a1545b6ed0d0c1788ca9369a847750f5652ffa0ca7f7b7d3hashransomware802
16afa928cd820a572bd47e798f481c46hashransomware802
b0cfa2089802634ffb8c77962cdb18317a6332d4hashransomware802
54a6743781fd4ceb720331fce92f16186931192dhashransomware802
259fd28f9e66159d5a30b86688fec184hashransomware802
42a99a5effdc1d02f6b622537de881e1hashransomware802
64a0ab00d90682b1807c5d7da1a4ae67cde4c5757fc7d995d8f126f0ec8ae983hashransomware802
eead44c0af7ddb12cece1a6125cf213bab3c22511cd59aff9d63dcfddb7d4386hash804
edbf152ed9ac79e5d9e0111d1071af48hashransomware802
7890b116d13a52efe696ce1e2c0ed83029775cf4bea836ce551e71d222ee116fhashransomware802
442af2726e22f512b49f67bcdbf7c0d1e806aa8bhashransomware802
8bd16897409ae5d5667c345276d2532f493c0f98hashransomware802
52fda5c1b9704544f32ee98d9060e689hashransomware802
2b2e657ae1bc2fdcdfe5201a8e0e5224hashransomware802
f962e15c6efebb3c29fe399bb168066042b616affddd83f72570c979184ec55chashransomware802
686213cc11d36af764de824801bced9366dfca3823fe0d51b752f74149bcf1f4sha256ransomware801
b0e292346b4ab3f83fadd8abcce7cfc5b9d50ef73ad141e8bc4a4689fee13504hashransomware802

Showing the top 30 by severity of 656.