Real-world descriptions of how a group, tool or campaign used a technique.
13 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1561.002 Disk Structure Wipe |
MalwareShrinkLocker | ShrinkLocker has used Diskpart to format newly-created partitions. |
| T1561.002 Disk Structure Wipe |
MalwareWhisperGate | WhisperGate can overwrite the Master Book Record (MBR) on victim systems with a malicious 16-bit bootloader. |
| T1561.002 Disk Structure Wipe |
MalwareMultiLayer Wiper | MultiLayer Wiper opens a handle to |
| T1561.002 Disk Structure Wipe |
MalwareShamoon | Shamoon has been seen overwriting features of disk structure such as the MBR. |
| T1561.002 Disk Structure Wipe |
MalwareStoneDrill | StoneDrill can wipe the master boot record of an infected computer. |
| T1561.002 Disk Structure Wipe |
MalwareHermeticWiper | HermeticWiper has the ability to corrupt disk partitions, damage the Master Boot Record (MBR), and overwrite the Master File Table (MFT) of all available physical drives. |
| T1561.002 Disk Structure Wipe |
MalwareCaddyWiper | CaddyWiper has the ability to destroy information about a physical drive's partitions including the MBR, GPT, and partition entries. |
| T1561.002 Disk Structure Wipe |
MalwareBFG Agonizer | BFG Agonizer retrieves a device handle to |
| T1561.002 Disk Structure Wipe |
MalwareKillDisk | KillDisk overwrites the first sector of the Master Boot Record with “0x00”. |
| T1561.002 Disk Structure Wipe |
MalwareDEADWOOD | DEADWOOD opens and writes zeroes to the first 512 bytes of each drive, deleting the MBR. DEADWOOD then sends the control code |
| T1561.002 Disk Structure Wipe |
ToolDiskpart | Diskpart can be used to delete a partition or a volume. Diskpart can also be used to remove all partitions or volume formatting from the selected disk. |
| T1561.002 Disk Structure Wipe |
ToolRawDisk | RawDisk was used in Shamoon to help overwrite components of disk structure like the MBR and disk partitions. |
| T1561.002 Disk Structure Wipe |
MalwareZeroCleare | ZeroCleare can corrupt the file system and wipe the system drive on targeted hosts. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.