ATT&CKReferencesCrowdstrike DriveSlayer February 2022

Crowdstrike DriveSlayer February 2022

Thomas, W. et al. (2022, February 25). CrowdStrike Falcon Protects from New Wiper Malware Used in Ukraine Cyberattacks. Retrieved March 25, 2022.

Open the source

Techniques1

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples17

TechniqueUsed byProcedure example
T1027.015
Compression
MalwareHermeticWiper

HermeticWiper can compress 32-bit and 64-bit driver files with the Lempel-Ziv algorithm.

T1070
Indicator Removal
MalwareHermeticWiper

HermeticWiper can disable pop-up information about folders and desktop items and delete Registry keys to hide malicious services.

T1070.004
File Deletion
MalwareHermeticWiper

HermeticWiper has the ability to overwrite its own file with random bites.

T1082
System Information Discovery
MalwareHermeticWiper

HermeticWiper can determine the OS version and bitness on a targeted host.

T1106
Native API
MalwareHermeticWiper

HermeticWiper can call multiple Windows API functions used for privilege escalation, service execution, and to overwrite random bites of data.

T1112
Modify Registry
MalwareHermeticWiper

HermeticWiper has the ability to modify Registry keys to disable crash dumps, colors for compressed files, and pop-up information about folders and desktop items.

T1134
Access Token Manipulation
MalwareHermeticWiper

HermeticWiper can use `AdjustTokenPrivileges` to grant itself privileges for debugging with `SeDebugPrivilege`, creating backups with `SeBackupPrivilege`, loading drivers with `SeLoadDriverPrivilege`, and shutting down a local system with `SeShutdownPrivilege`.

T1140
Deobfuscate/Decode Files or Information
MalwareHermeticWiper

HermeticWiper can decompress and copy driver files using `LZCopy`.

T1490
Inhibit System Recovery
MalwareHermeticWiper

HermeticWiper can disable the VSS service on a compromised host using the service control manager.

T1497.003
Time Based Checks
MalwareHermeticWiper

HermeticWiper has the ability to receive a command parameter to sleep prior to carrying out destructive actions on a targeted host.

T1543.003
Windows Service
MalwareHermeticWiper

HermeticWiper can load drivers by creating a new service using the `CreateServiceW` API.

T1553.002
Code Signing
MalwareHermeticWiper

The HermeticWiper executable has been signed with a legitimate certificate issued to Hermetica Digital Ltd.

T1561.001
Disk Content Wipe
MalwareHermeticWiper

HermeticWiper has the ability to corrupt disk partitions and obtain raw disk access to destroy data.

T1561.002
Disk Structure Wipe
MalwareHermeticWiper

HermeticWiper has the ability to corrupt disk partitions, damage the Master Boot Record (MBR), and overwrite the Master File Table (MFT) of all available physical drives.

T1569.002
Service Execution
MalwareHermeticWiper

HermeticWiper can create system services to aid in executing the payload.

T1680
Local Storage Discovery
MalwareHermeticWiper

HermeticWiper can enumerate physical drives on a targeted host.

T1685
Disable or Modify Tools
MalwareHermeticWiper

HermeticWiper has the ability to set the `HKLM:\SYSTEM\\CurrentControlSet\\Control\\CrashControl\CrashDumpEnabled` Registry key to `0` in order to disable crash dumps.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.