Real-world descriptions of how a group, tool or campaign used a technique.
30 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1485 Data Destruction |
MalwarePowerDuke | PowerDuke has a command to write random data across a file and delete it. |
| T1485 Data Destruction |
MalwareAcidRain | AcidRain performs an in-depth wipe of the target filesystem and various attached storage devices through either a data overwrite or calling various IOCTLS to erase it. |
| T1485 Data Destruction |
MalwareProxysvc | Proxysvc can overwrite files indicated by the attacker before deleting them. |
| T1485 Data Destruction |
MalwareOlympic Destroyer | Olympic Destroyer overwrites files locally and on remote shares. |
| T1485 Data Destruction |
MalwareDynoWiper | DynoWiper has overwritten files with 16-byte sequences of random data generated by the Mersenne Twister algorithm using the Microsoft Windows native `CreateFileW()` function to open the file and the `SetFilePointerEx()` and `WriteFile()` functions to overwrite the file. Additionally, versions of DynoWiper can also delete files using the `DeleteFileW` API. |
| T1485 Data Destruction |
MalwareShrinkLocker | ShrinkLocker can initiate a destructive payload depending on the operating system check through resizing and reformatting portions of the victim machine's disk, leading to system instability and potential data corruption. |
| T1485 Data Destruction |
MalwareApostle | Apostle initially masqueraded as ransomware but actual functionality is a data destruction tool, supported by an internal name linked to an early version, |
| T1485 Data Destruction |
MalwareWhisperGate | WhisperGate can corrupt files by overwriting the first 1 MB with `0xcc` and appending random extensions. |
| T1485 Data Destruction |
MalwareAcidPour | AcidPour can perform an in-depth wipe of victim filesystems and attached storage devices through either data overwrite or calling various IOCTLS to erase them, similar to AcidRain. |
| T1485 Data Destruction |
MalwareSameCoin | SameCoin can overwrite designated files on targeted systems with random bytes. |
| T1485 Data Destruction |
MalwareDiavol | Diavol can delete specified files from a targeted system. |
| T1485 Data Destruction |
MalwareKazuar | Kazuar can overwrite files with random data before deleting them. |
| T1485 Data Destruction |
MalwareBlackEnergy | BlackEnergy 2 contains a "Destroy" plug-in that destroys data stored on victim hard drives by overwriting file contents. |
| T1485 Data Destruction |
MalwareMultiLayer Wiper | MultiLayer Wiper deletes files on network drives, but corrupts and overwrites with random data files stored locally. |
| T1485 Data Destruction |
MalwareXbash | Xbash has destroyed Linux-based databases as part of its ransomware capabilities. |
| T1485 Data Destruction |
MalwareShamoon | Shamoon attempts to overwrite operating system files and disk structures with image files. In a later variant, randomly generated data was used for data overwrites. |
| T1485 Data Destruction |
MalwareStoneDrill | StoneDrill has a disk wiper module that targets files other than those in the Windows directory. |
| T1485 Data Destruction |
MalwareHermeticWiper | HermeticWiper can recursively wipe folders and files in `Windows`, `Program Files`, `Program Files(x86)`, `PerfLogs`, `Boot, System`, `Volume Information`, and `AppData` folders using `FSCTL_MOVE_FILE`. HermeticWiper can also overwrite symbolic links and big files in `My Documents` and on the Desktop with random bytes. |
| T1485 Data Destruction |
MalwareREvil | REvil has the capability to destroy files and folders. |
| T1485 Data Destruction |
MalwareCaddyWiper | CaddyWiper can work alphabetically through drives on a compromised system to take ownership of and overwrite all files. |
| T1485 Data Destruction |
MalwareMeteor | Meteor can fill a victim's files and directories with zero-bytes in replacement of real content before deleting them. |
| T1485 Data Destruction |
MalwareShai-Hulud | Shai-Hulud has destroyed the victim’s home directory by overwriting and deleting every writable file within the user's home folder. Shai-Hulud has also utilized the `shred` command on Linux devices. |
| T1485 Data Destruction |
MalwareKillDisk | KillDisk deletes system files to make the OS unbootable. KillDisk also targets and deletes files with 35 different file extensions. |
| T1485 Data Destruction |
MalwareIndustroyer | Industroyer’s data wiper module clears registry keys and overwrites both ICS configuration and Windows files. |
| T1485 Data Destruction |
MalwareLazyWiper | LazyWiper has overwritten files with pseudorandom 32‑byte sequences written at 16‑byte intervals making the file unrecoverable. |
| T1485 Data Destruction |
MalwareDEADWOOD | DEADWOOD overwrites files on victim systems with random data to effectively destroy them. |
| T1485 Data Destruction |
ToolRawDisk | RawDisk was used in Shamoon to write to protected system locations such as the MBR and disk partitions in an effort to destroy data. |
| T1485 Data Destruction |
ToolSDelete | SDelete deletes data in a way that makes it unrecoverable. |
| T1485 Data Destruction |
MalwareMini Shai-Hulud | Mini Shai-Hulud has wiped data on devices that fall within specified parameters to include those that resolve to specific geolocations including Iran and Israel. Mini Shai-Hulud has also implemented a dead-man’s switch that wipes the victims home directory if the operator revokes a GitHub token created by the adversary. |
| T1485 Data Destruction |
MalwareCanisterWorm | CanisterWorm has targeted wiper components that can delete entire clusters and execute recursive file deletions on non-containerized hosts. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.