Guerrero-Saade, J. (2022, February 23). HermeticWiper | New Destructive Malware Used In Cyber Attacks on Ukraine. Retrieved March 25, 2022.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1082 System Information Discovery |
MalwareHermeticWiper | HermeticWiper can determine the OS version and bitness on a targeted host. |
| T1083 File and Directory Discovery |
MalwareHermeticWiper | HermeticWiper can enumerate common folders such as My Documents, Desktop, and AppData. |
| T1106 Native API |
MalwareHermeticWiper | HermeticWiper can call multiple Windows API functions used for privilege escalation, service execution, and to overwrite random bites of data. |
| T1112 Modify Registry |
MalwareHermeticWiper | HermeticWiper has the ability to modify Registry keys to disable crash dumps, colors for compressed files, and pop-up information about folders and desktop items. |
| T1529 System Shutdown/Reboot |
MalwareHermeticWiper | HermeticWiper can initiate a system shutdown. |
| T1561.001 Disk Content Wipe |
MalwareHermeticWiper | HermeticWiper has the ability to corrupt disk partitions and obtain raw disk access to destroy data. |
| T1561.002 Disk Structure Wipe |
MalwareHermeticWiper | HermeticWiper has the ability to corrupt disk partitions, damage the Master Boot Record (MBR), and overwrite the Master File Table (MFT) of all available physical drives. |
| T1569.002 Service Execution |
MalwareHermeticWiper | HermeticWiper can create system services to aid in executing the payload. |
| T1680 Local Storage Discovery |
MalwareHermeticWiper | HermeticWiper can enumerate physical drives on a targeted host. |
| T1685 Disable or Modify Tools |
MalwareHermeticWiper | HermeticWiper has the ability to set the `HKLM:\SYSTEM\\CurrentControlSet\\Control\\CrashControl\CrashDumpEnabled` Registry key to `0` in order to disable crash dumps. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.