クラス: Trojan-Ransom
このタイプのトロイの木馬は、被害者のコンピュータ上のデータを変更して、被害者がデータを使用できなくなったり、コンピュータが正しく動作しないようにします。データが「人質になった」(ブロックされているか暗号化されている)と、ユーザーは身代金要求を受け取ります。身代金の要求は、被害者に悪質なユーザーのお金を送るように指示します。これを受け取り、サイバー犯罪者は被害者にデータを復元したり、コンピュータのパフォーマンスを復元するためのプログラムを送信します。プラットフォーム: Win32
Win32は、32ビットアプリケーションの実行をサポートするWindows NTベースのオペレーティングシステム(Windows XP、Windows 7など)上のAPIです。世界で最も広く普及しているプログラミングプラットフォームの1つです。ファミリー: Trojan-Ransom.Win32.Gen
No family descriptionExamples
78CF090F00D513978C664ABF2C85EDD5Tactics and Techniques: Mitre*
TA0011
Command and Control
The adversary is trying to communicate with compromised systems to control them. Command and Control consists of techniques that adversaries may use to communicate with systems under their control within a victim network. Adversaries commonly attempt to mimic normal, expected traffic to avoid detection. There are many ways an adversary can establish command and control with various levels of stealth depending on the victim's network structure and defenses.
T1102
Web Service
Adversaries may use an existing, legitimate external Web service as a means for relaying data to/from a compromised system. Popular websites, cloud services, and social media acting as a mechanism for C2 may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to a compromise. Using common services, such as those offered by Google, Microsoft, or Twitter, makes it easier for adversaries to hide in expected noise. Web service providers commonly use SSL/TLS encryption, giving adversaries an added level of protection.
* © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.