-

MITRE Engenuity Releases Findings of New MITRE ATT&CK® Evaluations for 11 Managed Security Service Providers

ATT&CK Evaluations test cybersecurity providers against adversary behavior informed by menuPass and ALPHV/BlackCat Ransomware

MCLEAN, Va. & BEDFORD, Mass.--(BUSINESS WIRE)--MITRE Engenuity ATT&CK® Evaluations (ATT&CK Evals) released its second round of independent ATT&CK Evaluations for managed security services providers (MSSP). Through the lens of the MITRE ATT&CK knowledge base, this round of ATT&CK Evals focused on adversary behavior informed by menuPass (G0045), a Chinese-based threat group, and an ALPHV/BlackCat ransomware affiliate.

William Booth, general manager, ATT&CK Evals, MITRE Engenuity, "The evidence-based results of the evaluation are a valuable resource for organizations in determining which security solutions best address their needs.”

Share

“In collaboration with the 11 providers who participated in this round of ATT&CK Evaluations Managed Services, we rigorously and transparently tested services against two well-known and prolific adversaries,” said William Booth, general manager, ATT&CK Evals, MITRE Engenuity. “The evidence-based results of the evaluation are a valuable resource for organizations in determining which security solutions best address their needs.”

The participants of this evaluation included:

Results of the evaluations are posted at https://attackevals.mitre-engenuity.org/.

This round of ATT&CK Evals emulated a multi-subsidiary compromise with overlapping operations focusing on defense evasion, exploiting trusted relationships, data encryption, and inhibiting system recovery. ATT&CK Evals mirrored the techniques and malware of menuPass, as well as an ALPHV/BlackCat affiliate’s deployment of BlackCat ransomware to Windows and Linux ESXi servers, highlighting data encryption/destruction and system recovery obstruction behaviors.

Active since at least 2006, menuPass (aka APT10) is believed to be sponsored by the Chinese Ministry of State Security. The group focuses on the exfiltration of sensitive data such as intellectual property and business intelligence in support of Chinese national security objectives. menuPass has targeted the aerospace, construction, engineering, government, and telecommunications sectors primarily in the U.S., Europe, Japan, and Southeast Asia.

“menuPass exemplifies the sophistication and versatility of modern adversaries,” said Amy Robertson, cyber threat intelligence engineering lead, ATT&CK Evals. “The group has demonstrated an affinity to living-off-the-land, while obscuring their activities through fileless execution and obfuscation to evade security controls and hinder analysis. They also have infiltrated trusted relationships to amplify their reach, representing a threat adept at exploiting vulnerabilities in both technology and trust itself."

ALPHV/BlackCat, a prolific Russian-speaking RaaS group that emerged in 2021, is linked to BlackMatter, DarkSide, REvil, and other RaaS groups. ALPHV/BlackCat utilizes ransomware coded in Rust, allowing for enhanced performance, flexibility, and cross-platform capabilities. Group affiliates are alleged to have targeted more than 1,000 victims across the globe, prior to the FBI’s disruption of the group.

“ALPHV/BlackCat represents a potent, multi-vector threat, capitalizing on technical innovations to maximize impact,” added Robertson. “The group’s ransomware-as-a-service (RaaS) model enabled affiliates to leverage defense evasion techniques like obfuscation and kill processes to disable defenses, and to use core data encryption functionality to cripple business operations across sectors.”

Within the evaluation, emulation of menuPass and ALPHV/BlackCat assessed a provider’s ability to detect threats that prioritize stealth, leverage trusted relationships and system tools, and inhibit system recovery through data destruction and encryption.

ABOUT MITRE ENGENUITY

MITRE Engenuity, a subsidiary of MITRE, is a tech foundation for public good. MITRE’s mission-driven teams are dedicated to solving problems for a safer world. Through our public-private partnerships and federally funded R&D centers, we work across government and in partnership with industry to tackle challenges to the safety, stability, and well-being of our nation.

MITRE Engenuity brings MITRE’s deep technical know-how and systems thinking to the private sector to solve complex challenges that government alone cannot solve. MITRE Engenuity catalyzes the collective R&D strength of the broader U.S. federal government, academia, and private sector to tackle national and global challenges. www.mitre-engenuity.org

ABOUT MITRE ENGENUITY ATT&CK® EVALUATIONS

ATT&CK® Evaluations is built on the backbone of MITRE’s objective insight and conflict-free perspective. Cybersecurity vendors turn to the ATT&CK Evals program to improve their offerings and to provide defenders with insights into their product’s capabilities and performance. ATT&CK Evals enables defenders to make better informed decisions on how to leverage the products that secure their networks. The program follows a rigorous, transparent methodology, using a collaborative, threat-informed, purple-teaming approach that brings together vendors and MITRE experts to evaluate solutions within the context of ATT&CK. In line with MITRE Engenuity’s commitment to serve the public good, ATT&CK Evals results and threat emulation plans are freely accessible. https://attackevals.mitre-engenuity.org/

Contacts

Lisa Fasold, media@mitre.org

MITRE


Release Versions

Contacts

Lisa Fasold, media@mitre.org

Social Media Profiles
More News From MITRE

MITRE and FAA Introduce Novel Aerospace Large Language Model Evaluation Benchmark

MCLEAN, Va.--(BUSINESS WIRE)--The Federal Aviation Administration (FAA) and MITRE are introducing a new benchmark to enable the evaluation and assessment of large language models (LLMs) for aerospace tasks. Given the safety-critical nature of aerospace, it is imperative that LLMs undergo thorough evaluation prior to their integration into systems. The Aerospace Language Understanding Evaluation (ALUE) benchmark provides a crucial tool for guiding the assurance of LLMs tailored to the unique dem...

New Defense Acquisition Framework to Accelerate Technology Transition to Warfighters

MCLEAN, Va., & BEDFORD, Mass.--(BUSINESS WIRE)--The National Security Engineering Center (NSEC), a federally funded research and development center (FFRDC) operated by MITRE, unveiled the Transition Maturity Framework (TMaF) today. TMaF is a comprehensive defense acquisition framework developed to streamline the transition of innovative technologies from research labs to active deployment with U.S. warfighters. The framework addresses persistent challenges by providing a structured acquisition...

Lloyds Banking Group Becomes First U.K. Financial Services Benefactor of MITRE ATT&CK®

MCLEAN, Va. & LONDON--(BUSINESS WIRE)--Lloyds Banking Group has become the first U.K. financial services benefactor of MITRE ATT&CK® to help globally advance threat-informed defense. The MITRE ATT&CK open-source framework enables organizations to understand how adversaries operate so they can better manage cyber risks and strengthen defenses. MITRE ATT&CK is a cornerstone of Lloyds Banking Group’s cyber defense strategy, providing a unified language to describe and analyze adversary...
Back to Newsroom