f33d by Prelude

Share this post
TTP Tuesday: Ransomware (Release 1)
feed.prelude.org

TTP Tuesday: Ransomware (Release 1)

Linux Ransomware using Live off the Land (LotL) Tools

Alex Manners
Dec 15, 2021
Share this post
TTP Tuesday: Ransomware (Release 1)
feed.prelude.org

Theme Overview

14 December 2021

Our current theme is ransomware, focusing on scenarios where threats use live off the land (LotL) binaries and custom payloads to accomplish their objectives. The ransomware theme will contain the following kill-chains:

  1. Linux Ransomware using Live off the Land (LotL) Tools (Current Release)

  2. Windows Ransomware using Live off the Land (LotL) Tools

  3. Linux Ransomware using Custom Tools

  4. Windows Ransomware using Custom Tools

Linux Ransomware using Live off the Land (LotL) Tools

This week's kill chain focuses on using native binaries available in Kali (Debian) Linux in order to perform a ransomware attack. We discover the current user's home directory and recursively compress it with the zip binary and a randomly generated password.

Check it out on the Prelude chains website.

Watch a demonstration:

Next week, we will be applying similar LotL methodology to create a Windows version of the kill chain. It will leverage native Windows system tools to discover and encrypt sensitive files and folders.

Staying up to date

Thanks for reading our first, new TTP Tuesday release! Please subscribe and reach out with any feedback. We love to hear from our community!

There are several ways to follow us and learn more about Prelude and our team members:

Get our products

Download Prelude Operator: https://www.prelude.org/download/current
See the latest kill chain and TTP Releases: https://chains.prelude.org/
See our open-source repositories: https://github.com/preludeorg

Join our community

Discord: https://discord.gg/gzUv4XNquu
Reddit: https://www.reddit.com/r/preludeorg/
Twitter: https://twitter.com/preludeorg

Read, watch, and listen

Listen to our Podcast: https://anchor.fm/preludeorg
Read our blog: https://feed.prelude.org/
Watch our live streams: https://www.twitch.tv/preludeorg
Watch our pre-recorded content: https://www.youtube.com/channel/UCZyx-PDZ_k7Vuzyqr4-qK9A

Follow our team

David: https://twitter.com/privateducky
Alex: https://twitter.com/khyberspache
Kris: https://twitter.com/Xanthonus

Share this post
TTP Tuesday: Ransomware (Release 1)
feed.prelude.org
Comments

Create your profile

0 subscriptions will be displayed on your profile (edit)

Skip for now

Only paid subscribers can comment on this post

Already a paid subscriber? Sign in

Check your email

For your security, we need to re-authenticate you.

Click the link we sent to , or click here to sign in.

TopNewCommunity

No posts

Ready for more?

© 2022 Prelude Research, Inc.
Privacy ∙ Terms ∙ Collection notice
Publish on Substack Get the app
Substack is the home for great writing