Vietnam Newsroom & Threat Intelligence
Clear sources · Careful assessments
NOTEDo not attribute a ransomware family from a file extension or a single ransom note.Vietnam time · UTC+7

TTP map

A stage-based framework for examining behavior, not an observed attack chain from an individual case.

Stages can repeat or occur in parallel. Encryption (T1486) is an Impact technique, not a separate MITRE ATT&CK tactic.

01
TA0001 · Initial Access

VPNs, management portals and login sessions need to be cross-checked.

Not linked to a case study
02
TA0002 · Execution

Processes, scripts, commands and parent–child relationships.

Not linked to a case study
03
TA0003 · Persistence

Tasks, services, accounts and startup configurations.

Not linked to a case study
04
TA0004 · Privilege Escalation

Changes to groups, tokens and account privileges.

Not linked to a case study
05
TA0006 · Credential Access

Artifacts of access to credential stores or authentication material.

Not linked to a case study
06
TA0007 · Discovery

Artifacts of asset, account and resource enumeration.

Not linked to a case study
07
TA0008 · Lateral Movement

Remote access sessions and execution on other devices.

Not linked to a case study
08
TA0010 · Exfiltration

Traffic and transfer artifacts; do not infer exfiltration from a single archive file.

Not linked to a case study
09
T1486 · Encryption

Changed files and write behavior. This is a technique within Impact.

Not linked to a case study
10
TA0040 · Impact

Loss of availability, data modification or interference with recovery.

Not linked to a case study
MITRE ATT&CK — Enterprise TacticsA behavioral reference framework; attacks do not necessarily follow one sequence.
MITRE ATT&CK — T1486: Data Encrypted for ImpactReference for encryption of data to cause disruption.

Each source's scope and date are recorded separately when available. A citation does not independently verify every assessment.