{
  "name": "U.S. v. Khoroshev et al. (LockBit Ransomware Operation) - ATT&CK Navigator Layer",
  "versions": {
    "attack": "15",
    "navigator": "4.5",
    "layer": "4.5"
  },
  "domain": "enterprise-attack",
  "description": "MITRE ATT&CK technique mappings with verified legal evidence for case lockbit-ransomware-takedown.",
  "filters": {
    "platforms": [
      "Windows",
      "Linux",
      "macOS",
      "Network",
      "PRE"
    ]
  },
  "sorting": 0,
  "layout": {
    "layout": "side",
    "aggregateFunction": "average",
    "showID": true,
    "showName": true,
    "showAggregateScores": false,
    "countUnscored": false
  },
  "hideDisabled": false,
  "techniques": [
    {
      "techniqueID": "T1486",
      "score": 1,
      "color": "#f59e0b",
      "comment": "LockBit conspirators systematically deployed ransomware binaries that encrypted victim servers and left ransom notes instructing victims to access a Tor negotiation portal.",
      "enabled": true,
      "metadata": [
        {
          "name": "locator",
          "value": "Indictment \u00b6 12, Page 6"
        },
        {
          "name": "status",
          "value": "reviewed"
        }
      ]
    },
    {
      "techniqueID": "T1567",
      "score": 1,
      "color": "#f59e0b",
      "comment": "Prior to encryption, defendants used StealBit and rclone to exfiltrate gigabytes of confidential trade secrets and patient health records to cloud storage accounts.",
      "enabled": true,
      "metadata": [
        {
          "name": "locator",
          "value": "Indictment \u00b6 18, Page 9"
        },
        {
          "name": "status",
          "value": "reviewed"
        }
      ]
    },
    {
      "techniqueID": "T1490",
      "score": 1,
      "color": "#f59e0b",
      "comment": "The malware invoked commands including 'vssadmin delete shadows /all /quiet' and 'wmic shadowcopy delete' to prevent administrative recovery.",
      "enabled": true,
      "metadata": [
        {
          "name": "locator",
          "value": "Indictment \u00b6 14, Page 7"
        },
        {
          "name": "status",
          "value": "reviewed"
        }
      ]
    },
    {
      "techniqueID": "T1190",
      "score": 1,
      "color": "#f59e0b",
      "comment": "Affiliates gained access by exploiting Citrix Bleed vulnerability CVE-2023-4966 in NetScaler ADC appliances.",
      "enabled": true,
      "metadata": [
        {
          "name": "locator",
          "value": "CISA Advisory AA23-325A"
        },
        {
          "name": "status",
          "value": "reviewed"
        }
      ]
    },
    {
      "techniqueID": "T1078",
      "score": 1,
      "color": "#f59e0b",
      "comment": "Conspirators purchased compromised administrative account logins on Genesis Market to authenticate through victim VPN portals.",
      "enabled": true,
      "metadata": [
        {
          "name": "locator",
          "value": "Complaint \u00b6 22"
        },
        {
          "name": "status",
          "value": "proposed"
        }
      ]
    },
    {
      "techniqueID": "T1047",
      "score": 1,
      "color": "#f59e0b",
      "comment": "LockBit 3.0 invoked Windows Management Instrumentation command lines to query domain controllers and enumerate reachable subnets.",
      "enabled": true,
      "metadata": [
        {
          "name": "locator",
          "value": "CISA Advisory AA23-165A \u00b6 12"
        },
        {
          "name": "status",
          "value": "reviewed"
        }
      ]
    },
    {
      "techniqueID": "T1562.001",
      "score": 1,
      "color": "#f59e0b",
      "comment": "LockBit payloads terminated endpoint protection services and cleared security event subscriptions before encryption.",
      "enabled": true,
      "metadata": [
        {
          "name": "locator",
          "value": "Indictment \u00b6 21, Page 11"
        },
        {
          "name": "status",
          "value": "reviewed"
        }
      ]
    },
    {
      "techniqueID": "T1558.003",
      "score": 1,
      "color": "#f59e0b",
      "comment": "LockBit affiliates executed Kerberoasting scripts against local Active Directory servers to request service tickets and extract Kerberos hashes for offline cracking.",
      "enabled": true,
      "metadata": [
        {
          "name": "locator",
          "value": "CISA Advisory AA23-165A Appendix"
        },
        {
          "name": "status",
          "value": "reviewed"
        }
      ]
    },
    {
      "techniqueID": "T1573",
      "score": 1,
      "color": "#f59e0b",
      "comment": "C2 communications between infected hosts and the LockBit backend utilized custom AES-256 encrypted channels over TCP port 443.",
      "enabled": true,
      "metadata": [
        {
          "name": "locator",
          "value": "Indictment \u00b6 15, Page 8"
        },
        {
          "name": "status",
          "value": "reviewed"
        }
      ]
    }
  ],
  "gradient": {
    "colors": [
      "#0e1420",
      "#f59e0b"
    ],
    "minValue": 0,
    "maxValue": 1
  },
  "legendItems": [
    {
      "label": "Mapped in primary evidence",
      "color": "#f59e0b"
    }
  ],
  "metadata": [
    {
      "name": "case_slug",
      "value": "lockbit-ransomware-takedown"
    },
    {
      "name": "case_title",
      "value": "U.S. v. Khoroshev et al. (LockBit Ransomware Operation)"
    }
  ]
}