Seth-Locker is a ransomware with some remote control capabilities that has been in use since at least 2021.[1]
Domain | ID | Name | Use | |
---|---|---|---|---|
Enterprise | T1059 | .003 | Command and Scripting Interpreter: Windows Command Shell |
Seth-Locker can execute commands via the command line shell.[1] |
Enterprise | T1486 | Data Encrypted for Impact |
Seth-Locker can encrypt files on a targeted system, appending them with the suffix .seth.[1] |
|
Enterprise | T1105 | Ingress Tool Transfer |
Seth-Locker has the ability to download and execute files on a compromised host.[1] |