Real-world descriptions of how a group, tool or campaign used a technique.
48 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1490 Inhibit System Recovery |
MalwareEKANS | EKANS removes backups of Volume Shadow Copies to disable any restoration capabilities. |
| T1490 Inhibit System Recovery |
MalwareRobbinHood | RobbinHood deletes shadow copies to ensure that all the data cannot be restored easily. |
| T1490 Inhibit System Recovery |
MalwareRansomHub | RansomHub has used `vssadmin.exe` to delete volume shadow copies. |
| T1490 Inhibit System Recovery |
MalwarePrestige | Prestige can delete the backup catalog from the target system using: `c:\Windows\System32\wbadmin.exe delete catalog -quiet` and can also delete volume shadow copies using: `\Windows\System32\vssadmin.exe delete shadows /all /quiet`. |
| T1490 Inhibit System Recovery |
MalwarePlaycrypt | Playcrypt can use AlphaVSS to delete shadow copies. |
| T1490 Inhibit System Recovery |
MalwareMedusa Ransomware | Medusa Ransomware has deleted recovery files such as shadow copies using `vssadmin.exe`. |
| T1490 Inhibit System Recovery |
MalwareOlympic Destroyer | Olympic Destroyer uses the native Windows utilities |
| T1490 Inhibit System Recovery |
MalwareBlackByte 2.0 Ransomware | BlackByte 2.0 Ransomware modifies volume shadow copies during execution in a way that destroys them on the victim machine. |
| T1490 Inhibit System Recovery |
MalwareWastedLocker | WastedLocker can delete shadow volumes. |
| T1490 Inhibit System Recovery |
MalwareProLock | ProLock can use vssadmin.exe to remove volume shadow copies. |
| T1490 Inhibit System Recovery |
MalwareInvisiMole | InvisiMole can can remove all system restore points. |
| T1490 Inhibit System Recovery |
MalwareConti | Conti can delete Windows Volume Shadow Copies using |
| T1490 Inhibit System Recovery |
MalwareDiavol | Diavol can delete shadow copies using the `IVssBackupComponents` COM object to call the `DeleteSnapshots` method. |
| T1490 Inhibit System Recovery |
MalwareBlackCat | BlackCat can delete shadow copies using `vssadmin.exe delete shadows /all /quiet` and `wmic.exe Shadowcopy Delete`; it can also modify the boot loader using `bcdedit /set {default} recoveryenabled No`. |
| T1490 Inhibit System Recovery |
MalwareRagnar Locker | Ragnar Locker can delete volume shadow copies using |
| T1490 Inhibit System Recovery |
MalwareAvaddon | Avaddon deletes backups and shadow copies using native system tools. |
| T1490 Inhibit System Recovery |
MalwareConficker | Conficker resets system restore points and deletes backup files. |
| T1490 Inhibit System Recovery |
MalwareHELLOKITTY | HELLOKITTY can delete volume shadow copies on compromised hosts. |
| T1490 Inhibit System Recovery |
MalwareBabuk | Babuk has the ability to delete shadow volumes using |
| T1490 Inhibit System Recovery |
MalwareDarkWatchman | DarkWatchman can delete shadow volumes using |
| T1490 Inhibit System Recovery |
MalwareMultiLayer Wiper | MultiLayer Wiper wipes the boot sector of infected systems to inhibit system recovery. |
| T1490 Inhibit System Recovery |
MalwareDEATHRANSOM | DEATHRANSOM can delete volume shadow copies on compromised hosts. |
| T1490 Inhibit System Recovery |
MalwareAkira | Akira will delete system volume shadow copies via PowerShell commands. |
| T1490 Inhibit System Recovery |
MalwareDarkGate | DarkGate can delete system restore points through the command |
| T1490 Inhibit System Recovery |
MalwareLockBit 3.0 | LockBit 3.0 can delete volume shadow copies. |
| T1490 Inhibit System Recovery |
MalwareNetwalker | Netwalker can delete the infected system's Shadow Volumes to prevent recovery. |
| T1490 Inhibit System Recovery |
MalwareWannaCry | WannaCry uses |
| T1490 Inhibit System Recovery |
MalwareRoyal | Royal can delete shadow copy backups with vssadmin.exe using the command `delete shadows /all /quiet`. |
| T1490 Inhibit System Recovery |
MalwareEmbargo | Embargo has cleared files from the recycle bin by invoking `SHEmptyRecycleBinW()` and disabled Windows recovery through `C:\Windows\System32\cmd.exe /q /c bcdedit /set {default} recoveryenabled no`. |
| T1490 Inhibit System Recovery |
MalwareBlack Basta | Black Basta can delete shadow copies using vssadmin.exe. Avertium Black Basta June 2022Check Point Black Basta October 2022Cyble Black Basta May 2022Deep Instinct Black Basta August 2022Minerva Labs Black Basta May 2022NCC Group Black Basta June 2022Palo Alto Networks Black Basta August 2022Trend Micro Black Basta May 2022Trend Micro Black Basta Spotlight September 2022 |
| T1490 Inhibit System Recovery |
MalwareMegaCortex | MegaCortex has deleted volume shadow copies using |
| T1490 Inhibit System Recovery |
MalwareBlackByte Ransomware | BlackByte Ransomware deletes all volume shadow copies and restore points among other actions to inhibit system recovery following ransomware deployment. |
| T1490 Inhibit System Recovery |
MalwareRyuk | Ryuk has used |
| T1490 Inhibit System Recovery |
MalwareHermeticWiper | HermeticWiper can disable the VSS service on a compromised host using the service control manager. |
| T1490 Inhibit System Recovery |
MalwarePysa | Pysa has the functionality to delete shadow copies. |
| T1490 Inhibit System Recovery |
MalwareLockBit 2.0 | LockBit 2.0 has the ability to delete volume shadow copies on targeted hosts. |
| T1490 Inhibit System Recovery |
MalwareJCry | JCry has been observed deleting shadow copies to ensure that data cannot be restored easily. |
| T1490 Inhibit System Recovery |
MalwareREvil | REvil can use vssadmin to delete volume shadow copies and bcdedit to disable recovery features. |
| T1490 Inhibit System Recovery |
MalwareROADSWEEP | ROADSWEEP has the ability to disable `SystemRestore` and Volume Shadow Copies. |
| T1490 Inhibit System Recovery |
MalwareClop | Clop can delete the shadow volumes with |
| T1490 Inhibit System Recovery |
MalwareBFG Agonizer | BFG Agonizer wipes the boot sector of infected machines to inhibit system recovery. |
| T1490 Inhibit System Recovery |
MalwareMeteor | Meteor can use `bcdedit` to delete different boot identifiers on a compromised host; it can also use `vssadmin.exe delete shadows /all /quiet` and `C:\\Windows\\system32\\wbem\\wmic.exe shadowcopy delete`. |
| T1490 Inhibit System Recovery |
MalwareMaze | Maze has attempted to delete the shadow volumes of infected machines, once before and once after the encryption process. |
| T1490 Inhibit System Recovery |
MalwareQilin | Qilin can execute `vssadmin.exe delete shadows /all /quiet` to remove volume shadow copies and can disable High Availability (HA) and Distributed Resource Scheduler (DRS) in vCenter clusters. |
| T1490 Inhibit System Recovery |
MalwareINC Ransomware | INC Ransomware can delete volume shadow copy backups from victim machines. |
| T1490 Inhibit System Recovery |
MalwareFIVEHANDS | FIVEHANDS has the ability to delete volume shadow copies on compromised hosts. |
| T1490 Inhibit System Recovery |
MalwareH1N1 | H1N1 disable recovery options and deletes shadow copies from the victim. |
| T1490 Inhibit System Recovery |
MalwareBitPaymer | BitPaymer attempts to remove the backup shadow files from the host using |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.