3attributed CVEs
26ATT&CK techniques
12.9IDF score (tooling uniqueness)
3exclusive CVEs
2021years active
About this actor
[C0018](https://attack.mitre.org/campaigns/C0018) was a month-long ransomware intrusion that successfully deployed [AvosLocker](https://attack.mitre.org/software/S1053) onto a compromised network. The unidentified actors gained initial access to the victim network through an exposed server and used a variety of open-source tools prior to executing [AvosLocker](https://attack.mitre.org/software/S1053).(Citation: Costa AvosLocker May 2022)(Citation: Cisco Talos Avos Jun 2022)
Source: MITRE ATT&CK
How we know this
- Data origin
- MITRE ATT&CK campaign Imported from the MITRE ATT&CK STIX bundle as a campaign object.
- Techniques
- MITRE ATT&CK STIX mappings — 26 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
- 2021 — 3 CVE published
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
CVE-2021-44832 | 7.7 | 6.6 | 0.9808 | 2021-12-28 | see CVE |
CVE-2021-45105 | 7.3 | 5.9 | 1.0000 | 2021-12-18 | see CVE |
CVE-2021-31206 | 6.8 | 7.6 | 0.1316 | 2021-07-14 | see CVE |
T1016System Network Configuration Discovery ↗T1021Remote Services ↗T1021.001Remote Desktop Protocol ↗T1027Obfuscated Files or Information ↗T1027.010Command Obfuscation ↗T1033System Owner/User Discovery ↗T1036Masquerading ↗T1036.005Match Legitimate Resource Name or Location ↗T1046Network Service Discovery ↗T1047Windows Management Instrumentation ↗T1059Command and Scripting Interpreter ↗T1059.001PowerShell ↗T1071Application Layer Protocol ↗T1071.001Web Protocols ↗T1072Software Deployment Tools ↗T1105Ingress Tool Transfer ↗T1190Exploit Public-Facing Application ↗T1218System Binary Proxy Execution ↗T1218.011Rundll32 ↗T1219Remote Access Tools ↗T1219.002Remote Desktop Software ↗T1486Data Encrypted for Impact ↗T1570Lateral Tool Transfer ↗T1571Non-Standard Port ↗T1588Obtain Capabilities ↗T1588.002Tool ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
SI-4 | 21 / 26 | 81% |
CM-6 | 19 / 26 | 73% |
CM-2 | 18 / 26 | 69% |
SI-3 | 18 / 26 | 69% |
CM-7 | 17 / 26 | 65% |
AC-3 | 14 / 26 | 54% |
CA-7 | 14 / 26 | 54% |
SI-7 | 12 / 26 | 46% |
AC-4 | 11 / 26 | 42% |
AC-6 | 11 / 26 | 42% |
SC-7 | 11 / 26 | 42% |
AC-2 | 10 / 26 | 38% |
SI-10 | 10 / 26 | 38% |
AC-5 | 8 / 26 | 31% |
CM-5 | 8 / 26 | 31% |
Co-occurring actors
None.
Similar actors
Similar TTPs
- INC Ransom 0.33
- HomeLand Justice 0.29
- C0015 0.29
- Blue Mockingbird 0.27
- C0021 0.27
Active in same years
- SolarWinds Compromise 1.00
- SharePoint ToolShell Exploitation 1.00
- APT1 1.00
- Deep Panda 1.00
- APT29 1.00