Malhotra, A. (2022, March 15). Threat Advisory: CaddyWiper. Retrieved March 23, 2022.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1082 System Information Discovery |
MalwareCaddyWiper | CaddyWiper can use `DsRoleGetPrimaryDomainInformation` to determine the role of the infected machine. CaddyWiper can also halt execution if the compromised host is identified as a domain controller. |
| T1106 Native API |
MalwareCaddyWiper | CaddyWiper has the ability to dynamically resolve and use APIs, including `SeTakeOwnershipPrivilege`. |
| T1222.001 Windows Permissions |
MalwareCaddyWiper | CaddyWiper can modify ACL entries to take ownership of files. |
| T1485 Data Destruction |
MalwareCaddyWiper | CaddyWiper can work alphabetically through drives on a compromised system to take ownership of and overwrite all files. |
| T1561.002 Disk Structure Wipe |
MalwareCaddyWiper | CaddyWiper has the ability to destroy information about a physical drive's partitions including the MBR, GPT, and partition entries. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.