{
  "name": "U.S. v. Yakubets & Turashev (Evil Corp / Dridex Banking Malware) - ATT&CK Navigator Layer",
  "versions": {
    "attack": "15",
    "navigator": "4.5",
    "layer": "4.5"
  },
  "domain": "enterprise-attack",
  "description": "MITRE ATT&CK technique mappings with verified legal evidence for case us-v-yakubets-evil-corp-dridex.",
  "filters": {
    "platforms": [
      "Windows",
      "Linux",
      "macOS",
      "Network",
      "PRE"
    ]
  },
  "sorting": 0,
  "layout": {
    "layout": "side",
    "aggregateFunction": "average",
    "showID": true,
    "showName": true,
    "showAggregateScores": false,
    "countUnscored": false
  },
  "hideDisabled": false,
  "techniques": [
    {
      "techniqueID": "T1566.001",
      "score": 1,
      "color": "#f59e0b",
      "comment": "Defendants distributed millions of phishing emails containing malicious macros disguised as invoices to infect corporate computers with Dridex.",
      "enabled": true,
      "metadata": [
        {
          "name": "locator",
          "value": "Indictment \u00b6 19, Page 11"
        },
        {
          "name": "status",
          "value": "reviewed"
        }
      ]
    },
    {
      "techniqueID": "T1555",
      "score": 1,
      "color": "#f59e0b",
      "comment": "Dridex injected web forms into web browsers to capture online banking credentials, passcodes, and transaction authorization numbers.",
      "enabled": true,
      "metadata": [
        {
          "name": "locator",
          "value": "Indictment \u00b6 24, Page 14"
        },
        {
          "name": "status",
          "value": "reviewed"
        }
      ]
    },
    {
      "techniqueID": "T1486",
      "score": 1,
      "color": "#f59e0b",
      "comment": "In later operations, conspirators deployed BitPaymer and WastedLocker ransomware against compromised networks to extort ransoms exceeding $5 million per victim.",
      "enabled": true,
      "metadata": [
        {
          "name": "locator",
          "value": "Treasury Designation Announcement"
        },
        {
          "name": "status",
          "value": "reviewed"
        }
      ]
    },
    {
      "techniqueID": "T1055",
      "score": 1,
      "color": "#f59e0b",
      "comment": "Dridex injected dynamic link library code into running Internet Explorer and Chrome browser processes to intercept HTTPS traffic.",
      "enabled": true,
      "metadata": [
        {
          "name": "locator",
          "value": "Indictment \u00b6 23, Page 13"
        },
        {
          "name": "status",
          "value": "reviewed"
        }
      ]
    },
    {
      "techniqueID": "T1547.001",
      "score": 1,
      "color": "#f59e0b",
      "comment": "The malware wrote autorun entries into HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run to maintain persistence across reboots.",
      "enabled": true,
      "metadata": [
        {
          "name": "locator",
          "value": "Indictment \u00b6 26, Page 15"
        },
        {
          "name": "status",
          "value": "reviewed"
        }
      ]
    },
    {
      "techniqueID": "T1053.005",
      "score": 1,
      "color": "#f59e0b",
      "comment": "Conspirators created scheduled tasks via schtasks.exe to trigger periodic secondary bot payload downloads.",
      "enabled": true,
      "metadata": [
        {
          "name": "locator",
          "value": "CISA Advisory AA19-339A"
        },
        {
          "name": "status",
          "value": "reviewed"
        }
      ]
    },
    {
      "techniqueID": "T1102",
      "score": 1,
      "color": "#f59e0b",
      "comment": "Dridex used public social media profile pages and paste sites as dead drop resolvers to retrieve active C2 IP addresses.",
      "enabled": true,
      "metadata": [
        {
          "name": "locator",
          "value": "CISA Technical Analysis Report"
        },
        {
          "name": "status",
          "value": "reviewed"
        }
      ]
    }
  ],
  "gradient": {
    "colors": [
      "#0e1420",
      "#f59e0b"
    ],
    "minValue": 0,
    "maxValue": 1
  },
  "legendItems": [
    {
      "label": "Mapped in primary evidence",
      "color": "#f59e0b"
    }
  ],
  "metadata": [
    {
      "name": "case_slug",
      "value": "us-v-yakubets-evil-corp-dridex"
    },
    {
      "name": "case_title",
      "value": "U.S. v. Yakubets & Turashev (Evil Corp / Dridex Banking Malware)"
    }
  ]
}