ATT&CKReferencesIBM ZeroCleare Wiper December 2019

IBM ZeroCleare Wiper December 2019

Kessem, L. (2019, December 4). New Destructive Wiper ZeroCleare Targets Energy Sector in the Middle East. Retrieved September 4, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples6

TechniqueUsed byProcedure example
T1059.001
PowerShell
MalwareZeroCleare

ZeroCleare can use a malicious PowerShell script to bypass Windows controls.

T1068
Exploitation for Privilege Escalation
MalwareZeroCleare

ZeroCleare has used a vulnerable signed VBoxDrv driver to bypass Microsoft Driver Signature Enforcement (DSE) protections and subsequently load the unsigned RawDisk driver.

T1078
Valid Accounts
GroupOilRig

OilRig has used compromised credentials to access other systems on a victim network.

T1110
Brute Force
GroupOilRig

OilRig has used brute force techniques to obtain credentials.

T1553.002
Code Signing
MalwareZeroCleare

ZeroCleare can deploy a vulnerable, signed driver on a compromised host to bypass operating system safeguards.

T1561.002
Disk Structure Wipe
MalwareZeroCleare

ZeroCleare can corrupt the file system and wipe the system drive on targeted hosts.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.