Ransomware Group intelligence
Roadsweep
InactiveTrack Roadsweep with 1 published victims in a single intelligence view.
Overview
Roadsweep is tracked by Breach House as a ransomware group with 1 published victims.
Albania is currently the most targeted country in this dataset.
No leak location metadata is currently available for this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (0)
No known leak locations available for this group.
Top Activity Sectors (1)
Typical Attacks (15)
▼How Roadsweep typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via ROADSWEEP.
-
T1059.003 Windows Command Shell Execution
What they do: ROADSWEEP can open cmd.exe to enable command execution.
What that means: Adversaries may abuse the Windows command shell for execution.
-
T1559 Inter-Process Communication Execution
What they do: ROADSWEEP can pipe command output to a targeted process.
What that means: Adversaries may abuse inter-process communication (IPC) mechanisms for local code or command execution.
-
What they do: ROADSWEEP has been placed in the start up folder to trigger execution upon user login.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: The ROADSWEEP binary contains RC4 encrypted embedded scripts.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.004 File Deletion Stealth
What they do: ROADSWEEP can use embedded scripts to remove itself from the infected host.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1140 Deobfuscate/Decode Files or Information Stealth
What they do: ROADSWEEP can decrypt embedded scripts prior to execution.
What that means: Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis.
-
T1480 Execution Guardrails Stealth
What they do: ROADSWEEP requires four command line arguments to execute correctly, otherwise it will produce a message box and halt execution.
What that means: Adversaries may use execution guardrails to constrain execution or actions based on adversary supplied and environment specific conditions that are expected to be present on the target.
-
T1553.002 Code Signing Defense Impairment
What they do: ROADSWEEP has been digitally signed with a certificate issued to the Kuwait Telecommunications Company KSC.
What that means: Adversaries may create, acquire, or steal code signing materials to sign their malware or tools.
-
T1083 File and Directory Discovery Discovery
What they do: ROADSWEEP can enumerate files on infected devices and avoid encrypting files with .exe, .dll, .sys, .lnk, or . lck extensions.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1120 Peripheral Device Discovery Discovery
What they do: ROADSWEEP can identify removable drives attached to the victim's machine.
What that means: Adversaries may attempt to gather information about attached peripheral devices and components connected to a computer system.
-
T1680 Local Storage Discovery Discovery
What they do: ROADSWEEP can enumerate logical drives on targeted devices.
What that means: Adversaries may enumerate local drives, disks, and/or volumes and their attributes like total or free space and volume serial number.
-
T1486 Data Encrypted for Impact Impact
What they do: ROADSWEEP can RC4 encrypt content in blocks on targeted systems.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: ROADSWEEP can disable critical services and processes.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
-
T1490 Inhibit System Recovery Impact
What they do: ROADSWEEP has the ability to disable `SystemRestore` and Volume Shadow Copies.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
-
T1491.001 Internal Defacement Impact
What they do: ROADSWEEP has dropped ransom notes in targeted folders prior to encrypting the files.
What that means: An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
Victims (1)
Search, filter and paginate the victim timeline for Roadsweep. Showing 1–1 of 1.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Albanian Government id3802 View details | Albania | Public Sector | — | |
|
No additional victim description available. |
|||||