S2W. (2022, January 18). Analysis of Destructive Malware (WhisperGate) targeting Ukraine. Retrieved March 14, 2022.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.013 Encrypted/Encoded File |
MalwareWhisperGate | WhisperGate can Base64 encode strings, store downloaded files in reverse byte order, and use the Eazfuscator tool to obfuscate its third stage. |
| T1036 Masquerading |
MalwareWhisperGate | WhisperGate has been disguised as a JPG extension to avoid detection as a malicious PE file. |
| T1059.001 PowerShell |
MalwareWhisperGate | WhisperGate can use PowerShell to support multiple actions including execution and defense evasion. |
| T1071.001 Web Protocols |
MalwareWhisperGate | WhisperGate can make an HTTPS connection to download additional files. |
| T1083 File and Directory Discovery |
MalwareWhisperGate | WhisperGate can locate files based on hardcoded file extensions. |
| T1102 Web Service |
MalwareWhisperGate | WhisperGate can download additional payloads hosted on a Discord channel. |
| T1105 Ingress Tool Transfer |
MalwareWhisperGate | WhisperGate can download additional stages of malware from a Discord CDN channel. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareWhisperGate | WhisperGate can deobfuscate downloaded files stored in reverse byte order and decrypt embedded resources using multiple XOR operations. |
| T1485 Data Destruction |
MalwareWhisperGate | WhisperGate can corrupt files by overwriting the first 1 MB with `0xcc` and appending random extensions. |
| T1497.003 Time Based Checks |
MalwareWhisperGate | WhisperGate can pause for 20 seconds to bypass antivirus solutions. |
| T1542.003 Bootkit |
MalwareWhisperGate | WhisperGate overwrites the MBR with a bootloader component that performs destructive wiping operations on hard drives and displays a fake ransom note when the host boots. |
| T1561.001 Disk Content Wipe |
MalwareWhisperGate | WhisperGate can overwrite sectors of a victim host's hard drive at periodic offsets. |
| T1561.002 Disk Structure Wipe |
MalwareWhisperGate | WhisperGate can overwrite the Master Book Record (MBR) on victim systems with a malicious 16-bit bootloader. |
| T1569.002 Service Execution |
MalwareWhisperGate | WhisperGate can download and execute AdvancedRun.exe via `sc.exe`. |
| T1685 Disable or Modify Tools |
MalwareWhisperGate | WhisperGate can download and execute AdvancedRun.exe to disable the Windows Defender Theat Protection service and set an exclusion path for the C:\ drive. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.