Ransomware Attack on City Government
A sophisticated ransomware attack (PLAY ransomware group) has infiltrated the City of Georgetown's municipal network through a phishing campaign targeting the finance department. The attack encrypts critical servers including tax databases, utility billing systems, permit management, and emergency services dispatch. The ransomware group exfiltrated 2TB of sensitive citizen data before encryption and is now demanding M in Monero. City employees are locked out of email, file shares, and all line-of-business applications. The attack was detected when the IT helpdesk received over 200 calls within 30 minutes about ransom notes appearing on screens across multiple departments. The city's SOC team identified that the initial access occurred 14 days ago via a spear-phishing email with a malicious Excel attachment (DragonEgg Loader). The threat actors have established persistence via scheduled tasks, created multiple admin accounts, disabled Windows Defender across 800 endpoints, and used Cobalt Strike beacons for C2 communication. Data exfiltration was detected to 5 external IPs with over 2TB of data transferred in the last 72 hours.
🎯 Objectives
- Identify all affected systems and determine the scope of the ransomware infection using incident response procedures
- Map the attack lifecycle using MITRE ATT&CK to understand the full kill chain from initial access to impact
- Determine whether to pay the ransom and establish a decision-making framework for ransom negotiations
- Contain the outbreak by isolating affected network segments while maintaining essential city services
- Develop a recovery plan prioritizing critical citizen services (emergency dispatch, water, power)
- Manage public communication and media relations to maintain citizen trust and provide accurate information
- Coordinate with law enforcement (FBI, CISA, Secret Service) for threat intelligence and legal proceedings
- Implement enhanced security controls based on MITRE ATT&CK gaps identified during the exercise
📋 Exercise Modules
- MODULE 1: Initial Detection & Triage (15 min) — Assess the alert, determine scope, activate IR team, engage external IR firm
- MODULE 2: MITRE ATT&CK Mapping & Analysis (20 min) — Map full attack chain to MITRE ATT&CK, identify security gaps, prioritize containment
- MODULE 3: Containment & Eradication (20 min) — Isolate network segments, preserve evidence, remove threat actor access, block C2 infrastructure
- MODULE 4: Ransom Decision & Stakeholder Communication (20 min) — Ransom payment decision, legal consultation, public communication strategy
- MODULE 5: Recovery & Restoration (15 min) — Prioritize system recovery, validate backups, restore from clean backups, implement security improvements
💬 Discussion Questions
- TACTIC TA0001 — Initial Access: How did the attacker gain entry? What email security controls failed? How can DMARC, DKIM, SPF be improved?
- TACTIC TA0002 — Execution: How did DragonEgg Loader execute? What application whitelisting or ASR rules could have blocked it?
- TACTIC TA0003 — Persistence: How were scheduled tasks and new admin accounts created without detection? What PAM controls are needed?
- TACTIC TA0004 — Privilege Escalation: What privilege escalation techniques were used? How did the attacker gain domain admin?
- TACTIC TA0005 — Defense Evasion: How was Windows Defender disabled across 800 endpoints? What EDR solution is needed?
- TACTIC TA0006 — Credential Access: What credentials were compromised? Are MFA and PIM/PAM properly implemented?
- TACTIC TA0007 — Discovery: What network reconnaissance occurred? How long was the attacker undiscovered?
- TACTIC TA0008 — Lateral Movement: How did the attacker move from finance department to critical infrastructure?
- TACTIC TA0009 — Collection: What data was collected before exfiltration? How to detect mass data access?
- TACTIC TA0010 — Exfiltration: How was 2TB of data exfiltrated without triggering DLP alerts?
- TACTIC TA0011 — Command and Control: How were Cobalt Strike beacons communicating? Can network segmentation prevent C2?
- TACTIC TA0040 — Impact: What is the financial impact of 14 days of city service disruption? How to calculate?
- Who has the authority to authorize ransom payment? What is the decision process?
- How to communicate with 250,000 citizens about the data breach and service disruption?
- What legal obligations exist under state breach notification laws and potential GDPR if EU citizen data is involved?
📚 References
- MITRE ATT&CK — Ransomware: https://attack.mitre.org/software/S1066/
- CISA Ransomware Guide: https://www.cisa.gov/stopransomware
- CISA MS-ISAC Ransomware Guide: https://www.cisa.gov/sites/default/files/publications/CISA_MS-ISAC_Ransomware%20Guide_508c.pdf
- NIST SP 800-61 Rev 2 — Incident Handling Guide: https://csrc.nist.gov/publications/detail/sp/800-61/rev-2/final
- MITRE ATT&CK Enterprise Matrix: https://attack.mitre.org/
- FBI Internet Crime Complaint Center (IC3): https://www.ic3.gov/
- CISA — Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- NIST Cybersecurity Framework (CSF) 2.0: https://www.nist.gov/cyberframework
- CISA — Stop Ransomware: https://www.cisa.gov/stopransomware
- Play Ransomware Group Analysis: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-339a