Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
Rows marked inferred are OSINT-extracted enrichment for actors without a MITRE Group ID — treat as analyst assessment, not authoritative ATT&CK attribution.
| Technique | Name | Tactic | Observed use |
|---|---|---|---|
| T1560.001 ↗inferred | Archive via Utility | Collection | BlackBerry: WinRAR used to archive victim data ahead of exfiltration. |
| T1105 ↗inferred | Ingress Tool Transfer | Command and Control | BlackBerry: operators installed Google Chrome on the compromised Horizon server to download their attack toolset, bypassing IE Enhanced Security Configuration. |
| T1219 ↗inferred | Remote Access Tools | Command and Control | BlackBerry: AnyDesk and Action1 RMM agents (action1_agent.exe, action1_remote.exe) deployed for persistent remote access; AnyDesk use mirrors leaked Conti playbooks. |
| T1003.001 ↗inferred | LSASS Memory | Credential Access | BlackBerry: LSASS process memory dumped to lsass.DMP and Mimikatz used to extract credentials. |
| T1555 ↗inferred | Credentials from Password Stores | Credential Access | BlackBerry: custom .NET 'Veeamp' dumper and Veeam-Get-Creds PowerShell script queried the VeeamBackup SQL Credentials table to steal backup-application credentials. |
| T1562.001 ↗ |
+12 more relationships — see the relationships browser.
| Disable or Modify Tools |
| Defense Evasion |
| BlackBerry: Avast Anti-Rootkit driver and GMER abused to disable antivirus/EDR prior to locker deployment. |
| T1046 ↗inferred | Network Service Discovery | Discovery | BlackBerry: SoftPerfect Network Scanner (netscan/netscan64) run to map internal hosts and services. |
| T1569.002 ↗inferred | Service Execution | Execution | BlackBerry: PsExec used for remote command execution across the estate. |
| T1567.002 ↗inferred | Exfiltration to Cloud Storage | Exfiltration | BlackBerry: MEGASync uploads to MEGA.io plus temporary file-sharing sites dropmefiles.com[.]ua and temp[.]sh used for data theft. |
| T1048 ↗inferred | Exfiltration Over Alternative Protocol | Exfiltration | BlackBerry: WinSCP and PuTTY staged for transferring stolen data out over SCP/SFTP-style channels. |
| T1486 ↗inferred | Data Encrypted for Impact | Impact | Windows locker.exe built from leaked Conti v3 source (.PUUUK extension, hex-edited ransom note) encrypted desktops and an ESXi cluster; Trend Micro (Aug 2023) Linux/ESXi encryptor uses AES-256-CTR, .monti extension, readme.txt in every directory, intermittent encryption by file size. |
| T1489 ↗inferred | Service Stop | Impact | Trend Micro: Linux/ESXi variant's --vmkill terminates running VMs (switched to -type=soft power-off to reduce detection) before encrypting datastores; --whitelist skips selected VMs. |
| T1491.001 ↗inferred | Internal Defacement | Impact | Trend Micro: Linux variant overwrites /etc/motd and index.html on ESXi hosts with the ransom announcement. |
| T1190 ↗inferred | Exploit Public-Facing Application | Initial Access | BlackBerry IR (Sept 2022): initial access via Log4Shell (CVE-2021-44228) against an internet-facing VMware Horizon Connection Broker. |
| T1021.001 ↗inferred | Remote Desktop Protocol | Lateral Movement | BlackBerry: RDP with harvested credentials used to reach additional servers and network shares before encryption. |
| T1550.002 ↗inferred | Pass the Hash | Lateral Movement | BlackBerry: Mimikatz used for pass-the-hash authentication to move between hosts. |
Regional co-occurrence is association, not prediction. These techniques appeared alongside Monti's activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by support-adjusted lift (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.
Which Microsoft 365 controls protect, detect, or respond to this actor's techniques — from the CTID Mappings Explorer (technique-level). Strength: significant / partial / minimal.
Defensive techniques that counter Monti's TTPs, from MITRE D3FEND. The ATT&CK↔D3FEND link is mitigation-mediated — treat these as candidate countermeasures, not prescriptions.