ATT&CKReferencesCisco CaddyWiper March 2022

Cisco CaddyWiper March 2022

Malhotra, A. (2022, March 15). Threat Advisory: CaddyWiper. Retrieved March 23, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples5

TechniqueUsed byProcedure example
T1082
System Information Discovery
MalwareCaddyWiper

CaddyWiper can use `DsRoleGetPrimaryDomainInformation` to determine the role of the infected machine. CaddyWiper can also halt execution if the compromised host is identified as a domain controller.

T1106
Native API
MalwareCaddyWiper

CaddyWiper has the ability to dynamically resolve and use APIs, including `SeTakeOwnershipPrivilege`.

T1222.001
Windows Permissions
MalwareCaddyWiper

CaddyWiper can modify ACL entries to take ownership of files.

T1485
Data Destruction
MalwareCaddyWiper

CaddyWiper can work alphabetically through drives on a compromised system to take ownership of and overwrite all files.

T1561.002
Disk Structure Wipe
MalwareCaddyWiper

CaddyWiper has the ability to destroy information about a physical drive's partitions including the MBR, GPT, and partition entries.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.