ATT&CKReferencesMedium S2W WhisperGate January 2022

Medium S2W WhisperGate January 2022

S2W. (2022, January 18). Analysis of Destructive Malware (WhisperGate) targeting Ukraine. Retrieved March 14, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples15

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
MalwareWhisperGate

WhisperGate can Base64 encode strings, store downloaded files in reverse byte order, and use the Eazfuscator tool to obfuscate its third stage.

T1036
Masquerading
MalwareWhisperGate

WhisperGate has been disguised as a JPG extension to avoid detection as a malicious PE file.

T1059.001
PowerShell
MalwareWhisperGate

WhisperGate can use PowerShell to support multiple actions including execution and defense evasion.

T1071.001
Web Protocols
MalwareWhisperGate

WhisperGate can make an HTTPS connection to download additional files.

T1083
File and Directory Discovery
MalwareWhisperGate

WhisperGate can locate files based on hardcoded file extensions.

T1102
Web Service
MalwareWhisperGate

WhisperGate can download additional payloads hosted on a Discord channel.

T1105
Ingress Tool Transfer
MalwareWhisperGate

WhisperGate can download additional stages of malware from a Discord CDN channel.

T1140
Deobfuscate/Decode Files or Information
MalwareWhisperGate

WhisperGate can deobfuscate downloaded files stored in reverse byte order and decrypt embedded resources using multiple XOR operations.

T1485
Data Destruction
MalwareWhisperGate

WhisperGate can corrupt files by overwriting the first 1 MB with `0xcc` and appending random extensions.

T1497.003
Time Based Checks
MalwareWhisperGate

WhisperGate can pause for 20 seconds to bypass antivirus solutions.

T1542.003
Bootkit
MalwareWhisperGate

WhisperGate overwrites the MBR with a bootloader component that performs destructive wiping operations on hard drives and displays a fake ransom note when the host boots.

T1561.001
Disk Content Wipe
MalwareWhisperGate

WhisperGate can overwrite sectors of a victim host's hard drive at periodic offsets.

T1561.002
Disk Structure Wipe
MalwareWhisperGate

WhisperGate can overwrite the Master Book Record (MBR) on victim systems with a malicious 16-bit bootloader.

T1569.002
Service Execution
MalwareWhisperGate

WhisperGate can download and execute AdvancedRun.exe via `sc.exe`.

T1685
Disable or Modify Tools
MalwareWhisperGate

WhisperGate can download and execute AdvancedRun.exe to disable the Windows Defender Theat Protection service and set an exclusion path for the C:\ drive.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.