{
  "name": "U.S. v. Andrienko et al. (Sandworm / GRU Unit 74455) - ATT&CK Navigator Layer",
  "versions": {
    "attack": "15",
    "navigator": "4.5",
    "layer": "4.5"
  },
  "domain": "enterprise-attack",
  "description": "MITRE ATT&CK technique mappings with verified legal evidence for case sandworm-notpetya-olympic-destroyer.",
  "filters": {
    "platforms": [
      "Windows",
      "Linux",
      "macOS",
      "Network",
      "PRE"
    ]
  },
  "sorting": 0,
  "layout": {
    "layout": "side",
    "aggregateFunction": "average",
    "showID": true,
    "showName": true,
    "showAggregateScores": false,
    "countUnscored": false
  },
  "hideDisabled": false,
  "techniques": [
    {
      "techniqueID": "T1485",
      "score": 1,
      "color": "#f59e0b",
      "comment": "The conspirators deployed the NotPetya malware, designed to irreversibly encrypt and destroy victim computer records worldwide while masquerading as ransomware.",
      "enabled": true,
      "metadata": [
        {
          "name": "locator",
          "value": "Indictment \u00b6 44, Page 22"
        },
        {
          "name": "status",
          "value": "reviewed"
        }
      ]
    },
    {
      "techniqueID": "T1190",
      "score": 1,
      "color": "#f59e0b",
      "comment": "Conspirators compromised the software update mechanism of M.E.Doc, an accounting software used extensively in Ukraine, to distribute the malicious NotPetya binary.",
      "enabled": true,
      "metadata": [
        {
          "name": "locator",
          "value": "Indictment \u00b6 38, Page 19"
        },
        {
          "name": "status",
          "value": "reviewed"
        }
      ]
    },
    {
      "techniqueID": "T1021.002",
      "score": 1,
      "color": "#f59e0b",
      "comment": "NotPetya leveraged EternalBlue (MS17-010) over SMB and PsExec to rapidly propagate across internal network subnets without user intervention.",
      "enabled": true,
      "metadata": [
        {
          "name": "locator",
          "value": "Indictment \u00b6 47, Page 24"
        },
        {
          "name": "status",
          "value": "reviewed"
        }
      ]
    },
    {
      "techniqueID": "T1003",
      "score": 1,
      "color": "#f59e0b",
      "comment": "The malware harvested passwords from computer memory using a bundled Mimikatz variant to impersonate network administrators.",
      "enabled": true,
      "metadata": [
        {
          "name": "locator",
          "value": "Indictment \u00b6 46, Page 23"
        },
        {
          "name": "status",
          "value": "reviewed"
        }
      ]
    },
    {
      "techniqueID": "T1566.001",
      "score": 1,
      "color": "#f59e0b",
      "comment": "Spearphishing emails containing weaponized Microsoft Word documents executing malicious macros were sent to Ukrainian electrical substation operators.",
      "enabled": true,
      "metadata": [
        {
          "name": "locator",
          "value": "Indictment \u00b6 15, Page 7"
        },
        {
          "name": "status",
          "value": "proposed"
        }
      ]
    },
    {
      "techniqueID": "T1055.012",
      "score": 1,
      "color": "#f59e0b",
      "comment": "Olympic Destroyer hollowed out the legitimate svchost.exe process to inject malicious wiper threads while mimicking regular operating system background activity.",
      "enabled": true,
      "metadata": [
        {
          "name": "locator",
          "value": "Indictment \u00b6 52, Page 27"
        },
        {
          "name": "status",
          "value": "reviewed"
        }
      ]
    },
    {
      "techniqueID": "T1036.005",
      "score": 1,
      "color": "#f59e0b",
      "comment": "NotPetya named its primary payload dllhost.dat inside C:\\Windows\\ to blend in with legitimate host process binaries.",
      "enabled": true,
      "metadata": [
        {
          "name": "locator",
          "value": "Indictment \u00b6 45, Page 23"
        },
        {
          "name": "status",
          "value": "reviewed"
        }
      ]
    },
    {
      "techniqueID": "T1543.003",
      "score": 1,
      "color": "#f59e0b",
      "comment": "The BlackEnergy malware created a persistent Windows service named 'Winexec' with automatic startup type.",
      "enabled": true,
      "metadata": [
        {
          "name": "locator",
          "value": "CISA Advisory ICS-ALERT-14-281-01B"
        },
        {
          "name": "status",
          "value": "reviewed"
        }
      ]
    },
    {
      "techniqueID": "T1499",
      "score": 1,
      "color": "#f59e0b",
      "comment": "Olympic Destroyer terminated domain controller authentication services to cause immediate host crash loops.",
      "enabled": true,
      "metadata": [
        {
          "name": "locator",
          "value": "Indictment \u00b6 54, Page 28"
        },
        {
          "name": "status",
          "value": "reviewed"
        }
      ]
    },
    {
      "techniqueID": "T1124",
      "score": 1,
      "color": "#f59e0b",
      "comment": "NotPetya scheduled a forced system reboot via shutdown.exe /r /t 60 synchronized to local system clock timestamps.",
      "enabled": true,
      "metadata": [
        {
          "name": "locator",
          "value": "CISA Advisory AA17-181A"
        },
        {
          "name": "status",
          "value": "reviewed"
        }
      ]
    }
  ],
  "gradient": {
    "colors": [
      "#0e1420",
      "#f59e0b"
    ],
    "minValue": 0,
    "maxValue": 1
  },
  "legendItems": [
    {
      "label": "Mapped in primary evidence",
      "color": "#f59e0b"
    }
  ],
  "metadata": [
    {
      "name": "case_slug",
      "value": "sandworm-notpetya-olympic-destroyer"
    },
    {
      "name": "case_title",
      "value": "U.S. v. Andrienko et al. (Sandworm / GRU Unit 74455)"
    }
  ]
}