Description
[DEATHRANSOM](https://attack.mitre.org/software/S0616) is ransomware written in C that has been used since at least 2020, and has potential overlap with [FIVEHANDS](https://attack.mitre.org/software/S0618) and [HELLOKITTY](https://attack.mitre.org/software/S0617).(Citation: FireEye FiveHands April 2021)
External References
Techniques Used by This Malware
- T1047 — Windows Management Instrumentation
- T1071.001 — Web Protocols
- T1082 — System Information Discovery
- T1083 — File and Directory Discovery
- T1105 — Ingress Tool Transfer
- T1135 — Network Share Discovery
- T1486 — Data Encrypted for Impact
- T1490 — Inhibit System Recovery
- T1614.001 — System Language Discovery