S1071Windows

S1071Rubeus

Platforms
1
ATT&CK
14.1
References
5

Description

[Rubeus](https://attack.mitre.org/software/S1071) is a C# toolset designed for raw Kerberos interaction that has been used since at least 2020, including in ransomware operations.(Citation: GitHub Rubeus March 2023)(Citation: FireEye KEGTAP SINGLEMALT October 2020)(Citation: DFIR Ryuk's Return October 2020)(Citation: DFIR Ryuk 2 Hour Speed Run November 2020)

Platforms· 1

Windows

References

  1. https://attack.mitre.org/software/S1071
  2. https://github.com/GhostPack/Rubeus
  3. https://www.fireeye.com/blog/threat-research/2020/10/kegtap-and-singlemalt-with-a-ransomware-chaser.html
  4. https://thedfirreport.com/2020/11/05/ryuk-speed-run-2-hours-to-ransom/
  5. https://thedfirreport.com/2020/10/08/ryuks-return/

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
Cerberos
Software
Ruby
Software
Ryuk
Software
BlackCat
Software
Royal
Software
Bumblebee
Sourced from MITRE ATT&CK Enterprise 14.1. Curated by Adam Lundqvist, SQUR.