ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1485×

30 examples

TechniqueUsed byProcedure example
T1485
Data Destruction
MalwarePowerDuke

PowerDuke has a command to write random data across a file and delete it.

T1485
Data Destruction
MalwareAcidRain

AcidRain performs an in-depth wipe of the target filesystem and various attached storage devices through either a data overwrite or calling various IOCTLS to erase it.

T1485
Data Destruction
MalwareProxysvc

Proxysvc can overwrite files indicated by the attacker before deleting them.

T1485
Data Destruction
MalwareOlympic Destroyer

Olympic Destroyer overwrites files locally and on remote shares.

T1485
Data Destruction
MalwareDynoWiper

DynoWiper has overwritten files with 16-byte sequences of random data generated by the Mersenne Twister algorithm using the Microsoft Windows native `CreateFileW()` function to open the file and the `SetFilePointerEx()` and `WriteFile()` functions to overwrite the file. Additionally, versions of DynoWiper can also delete files using the `DeleteFileW` API.

T1485
Data Destruction
MalwareShrinkLocker

ShrinkLocker can initiate a destructive payload depending on the operating system check through resizing and reformatting portions of the victim machine's disk, leading to system instability and potential data corruption.

T1485
Data Destruction
MalwareApostle

Apostle initially masqueraded as ransomware but actual functionality is a data destruction tool, supported by an internal name linked to an early version, wiper-action. Apostle writes random data to original files after an encrypted copy is created, along with resizing the original file to zero and changing time property metadata before finally deleting the original file.

T1485
Data Destruction
MalwareWhisperGate

WhisperGate can corrupt files by overwriting the first 1 MB with `0xcc` and appending random extensions.

T1485
Data Destruction
MalwareAcidPour

AcidPour can perform an in-depth wipe of victim filesystems and attached storage devices through either data overwrite or calling various IOCTLS to erase them, similar to AcidRain.

T1485
Data Destruction
MalwareSameCoin

SameCoin can overwrite designated files on targeted systems with random bytes.

T1485
Data Destruction
MalwareDiavol

Diavol can delete specified files from a targeted system.

T1485
Data Destruction
MalwareKazuar

Kazuar can overwrite files with random data before deleting them.

T1485
Data Destruction
MalwareBlackEnergy

BlackEnergy 2 contains a "Destroy" plug-in that destroys data stored on victim hard drives by overwriting file contents.

T1485
Data Destruction
MalwareMultiLayer Wiper

MultiLayer Wiper deletes files on network drives, but corrupts and overwrites with random data files stored locally.

T1485
Data Destruction
MalwareXbash

Xbash has destroyed Linux-based databases as part of its ransomware capabilities.

T1485
Data Destruction
MalwareShamoon

Shamoon attempts to overwrite operating system files and disk structures with image files. In a later variant, randomly generated data was used for data overwrites.

T1485
Data Destruction
MalwareStoneDrill

StoneDrill has a disk wiper module that targets files other than those in the Windows directory.

T1485
Data Destruction
MalwareHermeticWiper

HermeticWiper can recursively wipe folders and files in `Windows`, `Program Files`, `Program Files(x86)`, `PerfLogs`, `Boot, System`, `Volume Information`, and `AppData` folders using `FSCTL_MOVE_FILE`. HermeticWiper can also overwrite symbolic links and big files in `My Documents` and on the Desktop with random bytes.

T1485
Data Destruction
MalwareREvil

REvil has the capability to destroy files and folders.

T1485
Data Destruction
MalwareCaddyWiper

CaddyWiper can work alphabetically through drives on a compromised system to take ownership of and overwrite all files.

T1485
Data Destruction
MalwareMeteor

Meteor can fill a victim's files and directories with zero-bytes in replacement of real content before deleting them.

T1485
Data Destruction
MalwareShai-Hulud

Shai-Hulud has destroyed the victim’s home directory by overwriting and deleting every writable file within the user's home folder. Shai-Hulud has also utilized the `shred` command on Linux devices.

T1485
Data Destruction
MalwareKillDisk

KillDisk deletes system files to make the OS unbootable. KillDisk also targets and deletes files with 35 different file extensions.

T1485
Data Destruction
MalwareIndustroyer

Industroyer’s data wiper module clears registry keys and overwrites both ICS configuration and Windows files.

T1485
Data Destruction
MalwareLazyWiper

LazyWiper has overwritten files with pseudorandom 32‑byte sequences written at 16‑byte intervals making the file unrecoverable.

T1485
Data Destruction
MalwareDEADWOOD

DEADWOOD overwrites files on victim systems with random data to effectively destroy them.

T1485
Data Destruction
ToolRawDisk

RawDisk was used in Shamoon to write to protected system locations such as the MBR and disk partitions in an effort to destroy data.

T1485
Data Destruction
ToolSDelete

SDelete deletes data in a way that makes it unrecoverable.

T1485
Data Destruction
MalwareMini Shai-Hulud

Mini Shai-Hulud has wiped data on devices that fall within specified parameters to include those that resolve to specific geolocations including Iran and Israel. Mini Shai-Hulud has also implemented a dead-man’s switch that wipes the victims home directory if the operator revokes a GitHub token created by the adversary.

T1485
Data Destruction
MalwareCanisterWorm

CanisterWorm has targeted wiper components that can delete entire clusters and execute recursive file deletions on non-containerized hosts.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.