0attributed CVEs
46ATT&CK techniques
0.0IDF score (tooling uniqueness)
0exclusive CVEs
—years active
About this actor
[C0015](https://attack.mitre.org/campaigns/C0015) was a ransomware intrusion during which the unidentified attackers used [Bazar](https://attack.mitre.org/software/S0534), [Cobalt Strike](https://attack.mitre.org/software/S0154), and [Conti](https://attack.mitre.org/software/S0575), along with other tools, over a 5 day period. Security researchers assessed the actors likely used the widely-circulated [Conti](https://attack.mitre.org/software/S0575) ransomware playbook based on the observed pattern of activity and operator errors.(Citation: DFIR Conti Bazar Nov 2021)
Source: MITRE ATT&CK
How we know this
- Data origin
- MITRE ATT&CK campaign Imported from the MITRE ATT&CK STIX bundle as a campaign object.
- Techniques
- MITRE ATT&CK STIX mappings — 46 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
No activity events recorded.
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
| No attributed CVEs. | |||||
T1005Data from Local System ↗T1016System Network Configuration Discovery ↗T1018Remote System Discovery ↗T1021Remote Services ↗T1021.001Remote Desktop Protocol ↗T1027Obfuscated Files or Information ↗T1030Data Transfer Size Limits ↗T1036Masquerading ↗T1039Data from Network Shared Drive ↗T1047Windows Management Instrumentation ↗T1055Process Injection ↗T1055.001Dynamic-link Library Injection ↗T1057Process Discovery ↗T1059Command and Scripting Interpreter ↗T1059.003Windows Command Shell ↗T1059.005Visual Basic ↗T1059.007JavaScript ↗T1069Permission Groups Discovery ↗T1069.001Local Groups ↗T1069.002Domain Groups ↗T1074Data Staged ↗T1074.001Local Data Staging ↗T1083File and Directory Discovery ↗T1105Ingress Tool Transfer ↗T1124System Time Discovery ↗T1135Network Share Discovery ↗T1204User Execution ↗T1204.002Malicious File ↗T1218System Binary Proxy Execution ↗T1218.005Mshta ↗T1218.010Regsvr32 ↗T1218.011Rundll32 ↗T1219Remote Access Tools ↗T1219.002Remote Desktop Software ↗T1482Domain Trust Discovery ↗T1486Data Encrypted for Impact ↗T1553Subvert Trust Controls ↗T1553.002Code Signing ↗T1566Phishing ↗T1566.001Spearphishing Attachment ↗T1567Exfiltration Over Web Service ↗T1567.002Exfiltration to Cloud Storage ↗T1570Lateral Tool Transfer ↗T1588Obtain Capabilities ↗T1588.001Malware ↗T1588.002Tool ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
SI-4 | 28 / 46 | 61% |
CM-6 | 23 / 46 | 50% |
CM-2 | 22 / 46 | 48% |
SI-3 | 22 / 46 | 48% |
CM-7 | 18 / 46 | 39% |
AC-3 | 17 / 46 | 37% |
CA-7 | 16 / 46 | 35% |
SI-7 | 16 / 46 | 35% |
AC-6 | 15 / 46 | 33% |
SC-7 | 15 / 46 | 33% |
SI-10 | 14 / 46 | 30% |
AC-2 | 13 / 46 | 28% |
AC-4 | 13 / 46 | 28% |
SI-2 | 10 / 46 | 22% |
RA-5 | 9 / 46 | 20% |
Co-occurring actors
None.