ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1561.001×

13 examples

TechniqueUsed byProcedure example
T1561.001
Disk Content Wipe
MalwareAcidRain

AcidRain iterates over device file identifiers on the target, opens the device file, and either overwrites the file or calls various IOCTLS commands to erase it.

T1561.001
Disk Content Wipe
MalwareApostle

Apostle searches for files on available drives based on a list of extensions hard-coded into the sample for follow-on wipe activity.

T1561.001
Disk Content Wipe
MalwareWhisperGate

WhisperGate can overwrite sectors of a victim host's hard drive at periodic offsets.

T1561.001
Disk Content Wipe
MalwareAcidPour

AcidPour includes functionality to overwrite victim devices with the content of a buffer to wipe disk content.

T1561.001
Disk Content Wipe
MalwareBlackCat

BlackCat has the ability to wipe VM snapshots on compromised networks.

T1561.001
Disk Content Wipe
MalwareVPNFilter

VPNFilter has the capability to wipe a portion of an infected device's firmware.

T1561.001
Disk Content Wipe
MalwareDarkGate

DarkGate has deleted all files in the Mozilla directory using the following command: `/c del /q /f /s C:\Users\User\AppData\Roaming\Mozilla\firefox*`.

T1561.001
Disk Content Wipe
MalwareStoneDrill

StoneDrill can wipe the accessible physical or logical drives of the infected machine.

T1561.001
Disk Content Wipe
MalwareMegaCortex

MegaCortex can wipe deleted data from all drives using cipher.exe.

T1561.001
Disk Content Wipe
MalwareHermeticWiper

HermeticWiper has the ability to corrupt disk partitions and obtain raw disk access to destroy data.

T1561.001
Disk Content Wipe
MalwareDEADWOOD

DEADWOOD deletes files following overwriting them with random data.

T1561.001
Disk Content Wipe
ToolRawDisk

RawDisk has been used to directly access the hard disk to help overwrite arbitrarily sized portions of disk content.

T1561.001
Disk Content Wipe
Toolcipher.exe

cipher.exe can be used to overwrite deleted data in specified folders.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.