ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1490×

48 examples

TechniqueUsed byProcedure example
T1490
Inhibit System Recovery
MalwareEKANS

EKANS removes backups of Volume Shadow Copies to disable any restoration capabilities.

T1490
Inhibit System Recovery
MalwareRobbinHood

RobbinHood deletes shadow copies to ensure that all the data cannot be restored easily.

T1490
Inhibit System Recovery
MalwareRansomHub

RansomHub has used `vssadmin.exe` to delete volume shadow copies.

T1490
Inhibit System Recovery
MalwarePrestige

Prestige can delete the backup catalog from the target system using: `c:\Windows\System32\wbadmin.exe delete catalog -quiet` and can also delete volume shadow copies using: `\Windows\System32\vssadmin.exe delete shadows /all /quiet`.

T1490
Inhibit System Recovery
MalwarePlaycrypt

Playcrypt can use AlphaVSS to delete shadow copies.

T1490
Inhibit System Recovery
MalwareMedusa Ransomware

Medusa Ransomware has deleted recovery files such as shadow copies using `vssadmin.exe`.

T1490
Inhibit System Recovery
MalwareOlympic Destroyer

Olympic Destroyer uses the native Windows utilities vssadmin, wbadmin, and bcdedit to delete and disable operating system recovery features such as the Windows backup catalog and Windows Automatic Repair.

T1490
Inhibit System Recovery
MalwareBlackByte 2.0 Ransomware

BlackByte 2.0 Ransomware modifies volume shadow copies during execution in a way that destroys them on the victim machine.

T1490
Inhibit System Recovery
MalwareWastedLocker

WastedLocker can delete shadow volumes.

T1490
Inhibit System Recovery
MalwareProLock

ProLock can use vssadmin.exe to remove volume shadow copies.

T1490
Inhibit System Recovery
MalwareInvisiMole

InvisiMole can can remove all system restore points.

T1490
Inhibit System Recovery
MalwareConti

Conti can delete Windows Volume Shadow Copies using vssadmin.

T1490
Inhibit System Recovery
MalwareDiavol

Diavol can delete shadow copies using the `IVssBackupComponents` COM object to call the `DeleteSnapshots` method.

T1490
Inhibit System Recovery
MalwareBlackCat

BlackCat can delete shadow copies using `vssadmin.exe delete shadows /all /quiet` and `wmic.exe Shadowcopy Delete`; it can also modify the boot loader using `bcdedit /set {default} recoveryenabled No`.

T1490
Inhibit System Recovery
MalwareRagnar Locker

Ragnar Locker can delete volume shadow copies using vssadmin delete shadows /all /quiet.

T1490
Inhibit System Recovery
MalwareAvaddon

Avaddon deletes backups and shadow copies using native system tools.

T1490
Inhibit System Recovery
MalwareConficker

Conficker resets system restore points and deletes backup files.

T1490
Inhibit System Recovery
MalwareHELLOKITTY

HELLOKITTY can delete volume shadow copies on compromised hosts.

T1490
Inhibit System Recovery
MalwareBabuk

Babuk has the ability to delete shadow volumes using vssadmin.exe delete shadows /all /quiet.

T1490
Inhibit System Recovery
MalwareDarkWatchman

DarkWatchman can delete shadow volumes using vssadmin.exe.

T1490
Inhibit System Recovery
MalwareMultiLayer Wiper

MultiLayer Wiper wipes the boot sector of infected systems to inhibit system recovery.

T1490
Inhibit System Recovery
MalwareDEATHRANSOM

DEATHRANSOM can delete volume shadow copies on compromised hosts.

T1490
Inhibit System Recovery
MalwareAkira

Akira will delete system volume shadow copies via PowerShell commands.

T1490
Inhibit System Recovery
MalwareDarkGate

DarkGate can delete system restore points through the command cmd.exe /c vssadmin delete shadows /for=c: /all /quiet”.

T1490
Inhibit System Recovery
MalwareLockBit 3.0

LockBit 3.0 can delete volume shadow copies.

T1490
Inhibit System Recovery
MalwareNetwalker

Netwalker can delete the infected system's Shadow Volumes to prevent recovery.

T1490
Inhibit System Recovery
MalwareWannaCry

WannaCry uses vssadmin, wbadmin, bcdedit, and wmic to delete and disable operating system recovery features.

T1490
Inhibit System Recovery
MalwareRoyal

Royal can delete shadow copy backups with vssadmin.exe using the command `delete shadows /all /quiet`.

T1490
Inhibit System Recovery
MalwareEmbargo

Embargo has cleared files from the recycle bin by invoking `SHEmptyRecycleBinW()` and disabled Windows recovery through `C:\Windows\System32\cmd.exe /q /c bcdedit /set {default} recoveryenabled no`.

T1490
Inhibit System Recovery
MalwareBlack Basta

Black Basta can delete shadow copies using vssadmin.exe.

T1490
Inhibit System Recovery
MalwareMegaCortex

MegaCortex has deleted volume shadow copies using vssadmin.exe.

T1490
Inhibit System Recovery
MalwareBlackByte Ransomware

BlackByte Ransomware deletes all volume shadow copies and restore points among other actions to inhibit system recovery following ransomware deployment.

T1490
Inhibit System Recovery
MalwareRyuk

Ryuk has used vssadmin Delete Shadows /all /quiet to to delete volume shadow copies and vssadmin resize shadowstorage to force deletion of shadow copies created by third-party applications.

T1490
Inhibit System Recovery
MalwareHermeticWiper

HermeticWiper can disable the VSS service on a compromised host using the service control manager.

T1490
Inhibit System Recovery
MalwarePysa

Pysa has the functionality to delete shadow copies.

T1490
Inhibit System Recovery
MalwareLockBit 2.0

LockBit 2.0 has the ability to delete volume shadow copies on targeted hosts.

T1490
Inhibit System Recovery
MalwareJCry

JCry has been observed deleting shadow copies to ensure that data cannot be restored easily.

T1490
Inhibit System Recovery
MalwareREvil

REvil can use vssadmin to delete volume shadow copies and bcdedit to disable recovery features.

T1490
Inhibit System Recovery
MalwareROADSWEEP

ROADSWEEP has the ability to disable `SystemRestore` and Volume Shadow Copies.

T1490
Inhibit System Recovery
MalwareClop

Clop can delete the shadow volumes with vssadmin Delete Shadows /all /quiet and can use bcdedit to disable recovery options.

T1490
Inhibit System Recovery
MalwareBFG Agonizer

BFG Agonizer wipes the boot sector of infected machines to inhibit system recovery.

T1490
Inhibit System Recovery
MalwareMeteor

Meteor can use `bcdedit` to delete different boot identifiers on a compromised host; it can also use `vssadmin.exe delete shadows /all /quiet` and `C:\\Windows\\system32\\wbem\\wmic.exe shadowcopy delete`.

T1490
Inhibit System Recovery
MalwareMaze

Maze has attempted to delete the shadow volumes of infected machines, once before and once after the encryption process.

T1490
Inhibit System Recovery
MalwareQilin

Qilin can execute `vssadmin.exe delete shadows /all /quiet` to remove volume shadow copies and can disable High Availability (HA) and Distributed Resource Scheduler (DRS) in vCenter clusters.

T1490
Inhibit System Recovery
MalwareINC Ransomware

INC Ransomware can delete volume shadow copy backups from victim machines.

T1490
Inhibit System Recovery
MalwareFIVEHANDS

FIVEHANDS has the ability to delete volume shadow copies on compromised hosts.

T1490
Inhibit System Recovery
MalwareH1N1

H1N1 disable recovery options and deletes shadow copies from the victim.

T1490
Inhibit System Recovery
MalwareBitPaymer

BitPaymer attempts to remove the backup shadow files from the host using vssadmin.exe Delete Shadows /All /Quiet.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.