ATT&CKSoftwareStoneDrill

StoneDrill

S0380

Malware.View on attack.mitre.org

About this malware

StoneDrill is wiper malware discovered in destructive campaigns against both Middle Eastern and European targets in association with APT33.

Techniques used15

Procedure examples15

TechniqueProcedure example
T1012
Query Registry

StoneDrill has looked in the registry to find the default browser path.

T1027.013
Encrypted/Encoded File

StoneDrill has obfuscated its module with an alphabet-based table or XOR encryption.

T1047
Windows Management Instrumentation

StoneDrill has used the WMI command-line (WMIC) utility to run tasks.

T1055
Process Injection

StoneDrill has relied on injecting its payload directly into the process memory of the victim's preferred browser.

T1059.005
Visual Basic

StoneDrill has several VBS scripts used throughout the malware's lifecycle.

T1070.004
File Deletion

StoneDrill has been observed deleting the temporary files once they fulfill their task.

T1082
System Information Discovery

StoneDrill has the capability to discover the system OS, Windows version, architecture and environment.

T1105
Ingress Tool Transfer

StoneDrill has downloaded and dropped temporary files containing scripts; it additionally has a function to upload files from the victims machine.

T1113
Screen Capture

StoneDrill can take screenshots.

T1124
System Time Discovery

StoneDrill can obtain the current date and time of the victim machine.

T1485
Data Destruction

StoneDrill has a disk wiper module that targets files other than those in the Windows directory.

T1497
Virtualization/Sandbox Evasion

StoneDrill has used several anti-emulation techniques to prevent automated analysis by emulators or sandboxes.

T1518.001
Security Software Discovery

StoneDrill can check for antivirus and antimalware programs.

T1561.001
Disk Content Wipe

StoneDrill can wipe the accessible physical or logical drives of the infected machine.

T1561.002
Disk Structure Wipe

StoneDrill can wipe the master boot record of an infected computer.

Groups that use it1

Campaigns0

None recorded.

References2

  1. FireEye APT33 Sept 2017 Open source
    O'Leary, J., et al. (2017, September 20). Insights into Iranian Cyber Espionage: APT33 Targets Aerospace and Energy Sectors and has Ties to Destructive Malware. Retrieved February 15, 2018.
  2. Kaspersky StoneDrill 2017 Open source
    Kaspersky Lab. (2017, March 7). From Shamoon to StoneDrill: Wipers attacking Saudi organizations and beyond. Retrieved March 14, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.