KillDisk

S0607

Malware.View on attack.mitre.org

About this malware

KillDisk is a disk-wiping tool designed to overwrite files with random data to render the OS unbootable. It was first observed as a component of BlackEnergy malware during cyber attacks against Ukraine in 2015. KillDisk has since evolved into stand-alone malware used by a variety of threat actors against additional targets in Europe and Latin America; in 2016 a ransomware component was also incorporated into some KillDisk variants.

Techniques used15

Procedure examples15

TechniqueProcedure example
T1027
Obfuscated Files or Information

KillDisk uses VMProtect to make reverse engineering the malware more difficult.

T1036.004
Masquerade Task or Service

KillDisk registers as a service under the Plug-And-Play Support name.

T1057
Process Discovery

KillDisk has called GetCurrentProcess.

T1070.004
File Deletion

KillDisk has the ability to quit and delete itself.

T1083
File and Directory Discovery

KillDisk has used the FindNextFile command as part of its file deletion process.

T1106
Native API

KillDisk has called the Windows API to retrieve the hard disk handle and shut down the machine.

T1129
Shared Modules

KillDisk loads and executes functions from a DLL.

T1134
Access Token Manipulation

KillDisk has attempted to get the access token of a process by calling OpenProcessToken. If KillDisk gets the access token, then it attempt to modify the token privileges with AdjustTokenPrivileges.

T1485
Data Destruction

KillDisk deletes system files to make the OS unbootable. KillDisk also targets and deletes files with 35 different file extensions.

T1486
Data Encrypted for Impact

KillDisk has a ransomware component that encrypts files with an AES key that is also RSA-1028 encrypted.

T1489
Service Stop

KillDisk terminates various processes to get the user to reboot the victim machine.

T1529
System Shutdown/Reboot

KillDisk attempts to reboot the machine by terminating specific processes.

T1561.002
Disk Structure Wipe

KillDisk overwrites the first sector of the Master Boot Record with “0x00”.

T1680
Local Storage Discovery

KillDisk retrieves the hard disk name by calling the CreateFileA to \\.\PHYSICALDRIVE0 API.

T1685.005
Clear Windows Event Logs

KillDisk deletes Application, Security, Setup, and System Windows Event Logs.

Groups that use it2

Campaigns1

References4

  1. ESEST Black Energy Jan 2016 Open source
    Cherepanov, A.. (2016, January 3). BlackEnergy by the SSHBearDoor: attacks against Ukrainian news media and electric industry. Retrieved May 18, 2016.
  2. KillDisk Ransomware Open source
    Catalin Cimpanu. (2016, December 29). KillDisk Disk-Wiping Malware Adds Ransomware Component. Retrieved January 12, 2021.
  3. Trend Micro KillDisk 1 Open source
    Fernando Merces, Byron Gelera, Martin Co. (2018, June 7). KillDisk Variant Hits Latin American Finance Industry. Retrieved January 12, 2021.
  4. Trend Micro KillDisk 2 Open source
    Gilbert Sison, Rheniel Ramos, Jay Yaneza, Alfredo Oliveira. (2018, January 15). KillDisk Variant Hits Latin American Financial Groups. Retrieved January 12, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.