ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1484.001
Group Policy Modification
MalwareHermeticWiper

HermeticWiper has the ability to deploy through an infected system's default domain policy.

T1484.001
Group Policy Modification
MalwareLockBit 2.0

LockBit 2.0 can modify Group Policy to disable Windows Defender and to automatically infect devices in Windows domains.

T1484.001
Group Policy Modification
MalwareEgregor

Egregor can modify the GPO to evade detection.

T1484.001
Group Policy Modification
MalwareMeteor

Meteor can use group policy to push a scheduled task from the AD to all network machines.

T1484.001
Group Policy Modification
MalwareQilin

Qilin has pushed a scheduled task via a Group Policy Object for payload execution.

T1484.001
Group Policy Modification
ToolEmpire

Empire can use New-GPOImmediateTask to modify a GPO that will install and execute a malicious Scheduled Task/Job.

T1484.002
Trust Modification
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 changed domain federation trust settings using Azure AD administrative permissions to configure the domain to accept authorization tokens signed by their own SAML signing certificate.

T1484.002
Trust Modification
GroupScattered Spider

Scattered Spider adds a federated identity provider to the victim’s SSO tenant and activates automatic account linking.

T1484.002
Trust Modification
GroupStorm-0501

Storm-0501 created a new federated domain within the victim Microsoft Entra tenant using Global Administrator level access to establish a persistent backdoor for later use.

T1484.002
Trust Modification
ToolAADInternals

AADInternals can create a backdoor by converting a domain to a federated domain which will be able to authenticate any user across the tenant. AADInternals can also modify DesktopSSO information.

T1485
Data Destruction
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries utilized wiper malware to overwrite files using a 16-byte buffer that fully overwrites files 16 bytes or smaller or partially overwrites files greater than 16 bytes to speed up the process.

T1485
Data Destruction
Campaign2022 Ukraine Electric Power Attack

During the 2022 Ukraine Electric Power Attack, Sandworm Team deployed CaddyWiper on the victim’s IT environment systems to wipe files related to the OT capabilities, along with mapped drives, and physical drive partitions.

T1485
Data Destruction
GroupAPT38

APT38 has used a custom secure delete function to make deleted files unrecoverable.

T1485
Data Destruction
GroupSandworm Team

Sandworm Team has used CaddyWiper, SDelete, and the BlackEnergy KillDisk component to overwrite files on victim systems. Additionally, Sandworm Team has used the JUNKMAIL tool to overwrite files with null bytes.

T1485
Data Destruction
GroupStorm-0501

Storm-0501 has destroyed data and backup files.

T1485
Data Destruction
GroupLazarus Group

Lazarus Group has used a custom secure delete function to overwrite file contents with data from heap memory.

T1485
Data Destruction
GroupLAPSUS$

LAPSUS$ has deleted the target's systems and resources both on-premises and in the cloud.

T1485
Data Destruction
GroupVOID MANTICORE

VOID MANTICORE has conducted data wiping attacks on compromised systems. VOID MANTICORE has also manually deleted files from compromised hosts, to include selecting all files and then deleting them.

T1485
Data Destruction
MalwarePowerDuke

PowerDuke has a command to write random data across a file and delete it.

T1485
Data Destruction
MalwareAcidRain

AcidRain performs an in-depth wipe of the target filesystem and various attached storage devices through either a data overwrite or calling various IOCTLS to erase it.

T1485
Data Destruction
MalwareProxysvc

Proxysvc can overwrite files indicated by the attacker before deleting them.

T1485
Data Destruction
MalwareOlympic Destroyer

Olympic Destroyer overwrites files locally and on remote shares.

T1485
Data Destruction
MalwareDynoWiper

DynoWiper has overwritten files with 16-byte sequences of random data generated by the Mersenne Twister algorithm using the Microsoft Windows native `CreateFileW()` function to open the file and the `SetFilePointerEx()` and `WriteFile()` functions to overwrite the file. Additionally, versions of DynoWiper can also delete files using the `DeleteFileW` API.

T1485
Data Destruction
MalwareShrinkLocker

ShrinkLocker can initiate a destructive payload depending on the operating system check through resizing and reformatting portions of the victim machine's disk, leading to system instability and potential data corruption.

T1485
Data Destruction
MalwareApostle

Apostle initially masqueraded as ransomware but actual functionality is a data destruction tool, supported by an internal name linked to an early version, wiper-action. Apostle writes random data to original files after an encrypted copy is created, along with resizing the original file to zero and changing time property metadata before finally deleting the original file.

T1485
Data Destruction
MalwareWhisperGate

WhisperGate can corrupt files by overwriting the first 1 MB with `0xcc` and appending random extensions.

T1485
Data Destruction
MalwareAcidPour

AcidPour can perform an in-depth wipe of victim filesystems and attached storage devices through either data overwrite or calling various IOCTLS to erase them, similar to AcidRain.

T1485
Data Destruction
MalwareSameCoin

SameCoin can overwrite designated files on targeted systems with random bytes.

T1485
Data Destruction
MalwareDiavol

Diavol can delete specified files from a targeted system.

T1485
Data Destruction
MalwareKazuar

Kazuar can overwrite files with random data before deleting them.

T1485
Data Destruction
MalwareBlackEnergy

BlackEnergy 2 contains a "Destroy" plug-in that destroys data stored on victim hard drives by overwriting file contents.

T1485
Data Destruction
MalwareMultiLayer Wiper

MultiLayer Wiper deletes files on network drives, but corrupts and overwrites with random data files stored locally.

T1485
Data Destruction
MalwareXbash

Xbash has destroyed Linux-based databases as part of its ransomware capabilities.

T1485
Data Destruction
MalwareShamoon

Shamoon attempts to overwrite operating system files and disk structures with image files. In a later variant, randomly generated data was used for data overwrites.

T1485
Data Destruction
MalwareStoneDrill

StoneDrill has a disk wiper module that targets files other than those in the Windows directory.

T1485
Data Destruction
MalwareHermeticWiper

HermeticWiper can recursively wipe folders and files in `Windows`, `Program Files`, `Program Files(x86)`, `PerfLogs`, `Boot, System`, `Volume Information`, and `AppData` folders using `FSCTL_MOVE_FILE`. HermeticWiper can also overwrite symbolic links and big files in `My Documents` and on the Desktop with random bytes.

T1485
Data Destruction
MalwareREvil

REvil has the capability to destroy files and folders.

T1485
Data Destruction
MalwareCaddyWiper

CaddyWiper can work alphabetically through drives on a compromised system to take ownership of and overwrite all files.

T1485
Data Destruction
MalwareMeteor

Meteor can fill a victim's files and directories with zero-bytes in replacement of real content before deleting them.

T1485
Data Destruction
MalwareShai-Hulud

Shai-Hulud has destroyed the victim’s home directory by overwriting and deleting every writable file within the user's home folder. Shai-Hulud has also utilized the `shred` command on Linux devices.

T1485
Data Destruction
MalwareKillDisk

KillDisk deletes system files to make the OS unbootable. KillDisk also targets and deletes files with 35 different file extensions.

T1485
Data Destruction
MalwareIndustroyer

Industroyer’s data wiper module clears registry keys and overwrites both ICS configuration and Windows files.

T1485
Data Destruction
MalwareLazyWiper

LazyWiper has overwritten files with pseudorandom 32‑byte sequences written at 16‑byte intervals making the file unrecoverable.

T1485
Data Destruction
MalwareDEADWOOD

DEADWOOD overwrites files on victim systems with random data to effectively destroy them.

T1485
Data Destruction
ToolRawDisk

RawDisk was used in Shamoon to write to protected system locations such as the MBR and disk partitions in an effort to destroy data.

T1485
Data Destruction
ToolSDelete

SDelete deletes data in a way that makes it unrecoverable.

T1485
Data Destruction
MalwareMini Shai-Hulud

Mini Shai-Hulud has wiped data on devices that fall within specified parameters to include those that resolve to specific geolocations including Iran and Israel. Mini Shai-Hulud has also implemented a dead-man’s switch that wipes the victims home directory if the operator revokes a GitHub token created by the adversary.

T1485
Data Destruction
MalwareCanisterWorm

CanisterWorm has targeted wiper components that can delete entire clusters and execute recursive file deletions on non-containerized hosts.

T1485
Data Destruction
GroupTeamPCP

TeamPCP has deployed privileged DaemonSets to delete files on Kubernetes clusters and has executed recursive file deletions on non-containerized hosts.

T1485
Data Destruction
GroupShinyHunters

ShinyHunters has executed the `DeleteBucket` API call to delete buckets.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.