Real-world descriptions of how a group, tool or campaign used a technique.
13 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1561.001 Disk Content Wipe |
MalwareAcidRain | AcidRain iterates over device file identifiers on the target, opens the device file, and either overwrites the file or calls various IOCTLS commands to erase it. |
| T1561.001 Disk Content Wipe |
MalwareApostle | Apostle searches for files on available drives based on a list of extensions hard-coded into the sample for follow-on wipe activity. |
| T1561.001 Disk Content Wipe |
MalwareWhisperGate | WhisperGate can overwrite sectors of a victim host's hard drive at periodic offsets. |
| T1561.001 Disk Content Wipe |
MalwareAcidPour | AcidPour includes functionality to overwrite victim devices with the content of a buffer to wipe disk content. |
| T1561.001 Disk Content Wipe |
MalwareBlackCat | BlackCat has the ability to wipe VM snapshots on compromised networks. |
| T1561.001 Disk Content Wipe |
MalwareVPNFilter | VPNFilter has the capability to wipe a portion of an infected device's firmware. |
| T1561.001 Disk Content Wipe |
MalwareDarkGate | DarkGate has deleted all files in the Mozilla directory using the following command: `/c del /q /f /s C:\Users\User\AppData\Roaming\Mozilla\firefox*`. |
| T1561.001 Disk Content Wipe |
MalwareStoneDrill | StoneDrill can wipe the accessible physical or logical drives of the infected machine. |
| T1561.001 Disk Content Wipe |
MalwareMegaCortex | MegaCortex can wipe deleted data from all drives using |
| T1561.001 Disk Content Wipe |
MalwareHermeticWiper | HermeticWiper has the ability to corrupt disk partitions and obtain raw disk access to destroy data. |
| T1561.001 Disk Content Wipe |
MalwareDEADWOOD | DEADWOOD deletes files following overwriting them with random data. |
| T1561.001 Disk Content Wipe |
ToolRawDisk | RawDisk has been used to directly access the hard disk to help overwrite arbitrarily sized portions of disk content. |
| T1561.001 Disk Content Wipe |
Toolcipher.exe | cipher.exe can be used to overwrite deleted data in specified folders. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.