{
  "name": "ALPHV / BlackCat Ransomware Attack on Change Healthcare - ATT&CK Navigator Layer",
  "versions": {
    "attack": "15",
    "navigator": "4.5",
    "layer": "4.5"
  },
  "domain": "enterprise-attack",
  "description": "MITRE ATT&CK technique mappings with verified legal evidence for case alphv-blackcat-change-healthcare.",
  "filters": {
    "platforms": [
      "Windows",
      "Linux",
      "macOS",
      "Network",
      "PRE"
    ]
  },
  "sorting": 0,
  "layout": {
    "layout": "side",
    "aggregateFunction": "average",
    "showID": true,
    "showName": true,
    "showAggregateScores": false,
    "countUnscored": false
  },
  "hideDisabled": false,
  "techniques": [
    {
      "techniqueID": "T1078",
      "score": 1,
      "color": "#f59e0b",
      "comment": "The threat actor gained entry to a Change Healthcare Citrix portal using compromised credentials for an account that lacked multifactor authentication.",
      "enabled": true,
      "metadata": [
        {
          "name": "locator",
          "value": "Senate Finance Committee Testimony \u00b6 4"
        },
        {
          "name": "status",
          "value": "reviewed"
        }
      ]
    },
    {
      "techniqueID": "T1486",
      "score": 1,
      "color": "#f59e0b",
      "comment": "ALPHV BlackCat ransomware was executed across corporate data centers, encrypting critical clearinghouse databases and disabling pharmacy claim gateways.",
      "enabled": true,
      "metadata": [
        {
          "name": "locator",
          "value": "SEC Form 8-K Item 1.05"
        },
        {
          "name": "status",
          "value": "reviewed"
        }
      ]
    },
    {
      "techniqueID": "T1567",
      "score": 1,
      "color": "#f59e0b",
      "comment": "Attackers exfiltrated 6 terabytes of protected health information and sensitive patient records before demanding a 350 Bitcoin ransom.",
      "enabled": true,
      "metadata": [
        {
          "name": "locator",
          "value": "SEC Form 8-K Disclosure"
        },
        {
          "name": "status",
          "value": "reviewed"
        }
      ]
    },
    {
      "techniqueID": "T1041",
      "score": 1,
      "color": "#f59e0b",
      "comment": "Stolen medical claims and personally identifiable information were uploaded to adversary-controlled cloud servers prior to payload delivery.",
      "enabled": true,
      "metadata": [
        {
          "name": "locator",
          "value": "HHS OCR Notice"
        },
        {
          "name": "status",
          "value": "proposed"
        }
      ]
    },
    {
      "techniqueID": "T1133",
      "score": 1,
      "color": "#f59e0b",
      "comment": "Initial entry occurred via an external remote Citrix access gateway lacking multifactor authentication controls.",
      "enabled": true,
      "metadata": [
        {
          "name": "locator",
          "value": "UnitedHealth Senate Testimony \u00b6 5"
        },
        {
          "name": "status",
          "value": "reviewed"
        }
      ]
    },
    {
      "techniqueID": "T1087",
      "score": 1,
      "color": "#f59e0b",
      "comment": "ALPHV BlackCat actors queried active directory LDAP services to identify enterprise domain administrator accounts.",
      "enabled": true,
      "metadata": [
        {
          "name": "locator",
          "value": "CISA Advisory AA23-353A \u00b6 7"
        },
        {
          "name": "status",
          "value": "reviewed"
        }
      ]
    }
  ],
  "gradient": {
    "colors": [
      "#0e1420",
      "#f59e0b"
    ],
    "minValue": 0,
    "maxValue": 1
  },
  "legendItems": [
    {
      "label": "Mapped in primary evidence",
      "color": "#f59e0b"
    }
  ],
  "metadata": [
    {
      "name": "case_slug",
      "value": "alphv-blackcat-change-healthcare"
    },
    {
      "name": "case_title",
      "value": "ALPHV / BlackCat Ransomware Attack on Change Healthcare"
    }
  ]
}