ATT&CKReferencesMalwarebytes IssacWiper CaddyWiper March 2022

Malwarebytes IssacWiper CaddyWiper March 2022

Threat Intelligence Team. (2022, March 18). Double header: IsaacWiper and CaddyWiper . Retrieved April 11, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples3

TechniqueUsed byProcedure example
T1057
Process Discovery
MalwareCaddyWiper

CaddyWiper can obtain a list of current processes.

T1082
System Information Discovery
MalwareCaddyWiper

CaddyWiper can use `DsRoleGetPrimaryDomainInformation` to determine the role of the infected machine. CaddyWiper can also halt execution if the compromised host is identified as a domain controller.

T1083
File and Directory Discovery
MalwareCaddyWiper

CaddyWiper can enumerate all files and directories on a compromised host.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.