ATT&CKReferencesQualys Hermetic Wiper March 2022

Qualys Hermetic Wiper March 2022

Dani, M. (2022, March 1). Ukrainian Targets Hit by HermeticWiper, New Datawiper Malware. Retrieved March 25, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples14

TechniqueUsed byProcedure example
T1027.015
Compression
MalwareHermeticWiper

HermeticWiper can compress 32-bit and 64-bit driver files with the Lempel-Ziv algorithm.

T1082
System Information Discovery
MalwareHermeticWiper

HermeticWiper can determine the OS version and bitness on a targeted host.

T1083
File and Directory Discovery
MalwareHermeticWiper

HermeticWiper can enumerate common folders such as My Documents, Desktop, and AppData.

T1106
Native API
MalwareHermeticWiper

HermeticWiper can call multiple Windows API functions used for privilege escalation, service execution, and to overwrite random bites of data.

T1112
Modify Registry
MalwareHermeticWiper

HermeticWiper has the ability to modify Registry keys to disable crash dumps, colors for compressed files, and pop-up information about folders and desktop items.

T1134
Access Token Manipulation
MalwareHermeticWiper

HermeticWiper can use `AdjustTokenPrivileges` to grant itself privileges for debugging with `SeDebugPrivilege`, creating backups with `SeBackupPrivilege`, loading drivers with `SeLoadDriverPrivilege`, and shutting down a local system with `SeShutdownPrivilege`.

T1489
Service Stop
MalwareHermeticWiper

HermeticWiper has the ability to stop the Volume Shadow Copy service.

T1490
Inhibit System Recovery
MalwareHermeticWiper

HermeticWiper can disable the VSS service on a compromised host using the service control manager.

T1529
System Shutdown/Reboot
MalwareHermeticWiper

HermeticWiper can initiate a system shutdown.

T1553.002
Code Signing
MalwareHermeticWiper

The HermeticWiper executable has been signed with a legitimate certificate issued to Hermetica Digital Ltd.

T1561.002
Disk Structure Wipe
MalwareHermeticWiper

HermeticWiper has the ability to corrupt disk partitions, damage the Master Boot Record (MBR), and overwrite the Master File Table (MFT) of all available physical drives.

T1569.002
Service Execution
MalwareHermeticWiper

HermeticWiper can create system services to aid in executing the payload.

T1680
Local Storage Discovery
MalwareHermeticWiper

HermeticWiper can enumerate physical drives on a targeted host.

T1685
Disable or Modify Tools
MalwareHermeticWiper

HermeticWiper has the ability to set the `HKLM:\SYSTEM\\CurrentControlSet\\Control\\CrashControl\CrashDumpEnabled` Registry key to `0` in order to disable crash dumps.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.