T1486 Data Encrypted for Impact in real malware
ATT&CK technique T1486 Data Encrypted for Impact appears in 185 publicly analyzed samples on MalwareAnalyzer by Cyble, 0.2% of the analyzed corpus. Seven-day prevalence is falling (0 recent vs 8 prior). Most associated families: Ulise, HUILoader, Wanna, Lazy.
Tactics: impact
Prevalence in the corpus
- Samples exhibiting T1486: 185
- Share of analyzed corpus: 0.2%
- Last 7 days: 0 · prior 7 days: 8 (falling)
Malware families using T1486
Example samples
- Aurora15Connector.exe - malicious
- Aurora15Connector.exe - malicious
- Aurora15Connector.exe - malicious
- FB831A56_lock.exe - malicious
- Aurora15Connector.exe - malicious
- pp.exe - suspicious
- mimikaz.exe - malicious
- ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa.exe - malicious
- KeePass.exe - malicious
- f04e1c539d55d013f91331217c266f65350f32f22e72ac0bcb7d6a4115d1d4d1 - malicious
- c650d7ac82fc30afc81f94e7dd29c4598ea96c977acb8a96c6835211c9b6d188 - malicious
- ec8519640b20e745b41d4872be4f320efd34ebd9921e2ca9c131019f22a9d716 - malicious
- 5ad664ee2b91614eedc60ab3386b3bc70c87f26f94250f1ad2394c22ec28a04c - malicious
- 64baf07d0efe38d8bd3513c16aa481cfec9354b8c2ba966fee8a3a6ff5e60b30 - malicious
- ffafe2b75352673dbae846022f94d08b5f94e099b86f9041a7428b71f94303f5 - malicious
- f4dc4093baa6cdb4659d46b901f762245809992bc700ac57a9035c1618306909 - malicious
- 91351751997a825cc7bcb343e77071c068a579c6b51cc43923c198aac4590edd - malicious
- virussign.com_eb8208a284f2b7dbbd1fc66568e8f6d0.vir - malicious
- virussign.com_fc5da94e002665e2962d923de71483c0.vir - malicious
- virussign.com_5933fbd0b6ab381dd1bfab0dfbe4df00.vir - malicious
- 45c1d1e3473b0132fc927ecdc39e907cbe08f1b2bb221e72560eff1146632d21 - malicious
- virussign.com_95126c2e37b5aa5da8b8b85748ae1940.vir - malicious
- virussign.com_b4e386cf5c39fdd0c1168a1cc41200e0.vir - malicious
- 766be290e8d98ff9ce544ce6c4d898f721eb46a2ca69e738dfb191dae31ea7e5 - malicious
- Aurora15Connector.exe - malicious
Canonical technique definition: MITRE ATT&CK T1486 (ATT&CK v19.1, CC BY 4.0).
Frequently asked about T1486
- How common is ATT&CK T1486 (Data Encrypted for Impact) in real malware?
- ATT&CK technique T1486 Data Encrypted for Impact appears in 185 publicly analyzed samples on MalwareAnalyzer by Cyble, 0.2% of the analyzed corpus. Seven-day prevalence is falling (0 recent vs 8 prior). Most associated families: Ulise, HUILoader, Wanna, Lazy.
- Is T1486 becoming more common?
- Prevalence is falling: 0 samples in the last seven days against 8 in the seven days before. This measures submissions to MalwareAnalyzer by Cyble, so it reflects what is being submitted here rather than global attacker behaviour.
- Which malware families use T1486?
- In this corpus T1486 is most associated with Ulise (21), HUILoader (11), Wanna (9), Lazy (8). Counts are analyzed samples per family in which the technique was observed.
- What share of analyzed samples use T1486?
- 0.2% of the publicly analyzed corpus (185 of 114611 samples) exhibits T1486. Technique attribution comes from behavior captured during real sandbox detonation and from static analysis, not from a vendor label.
All ATT&CK techniques in the corpus · Latest analyzed threats