Malware.View on attack.mitre.org
KillDisk is a disk-wiping tool designed to overwrite files with random data to render the OS unbootable. It was first observed as a component of BlackEnergy malware during cyber attacks against Ukraine in 2015. KillDisk has since evolved into stand-alone malware used by a variety of threat actors against additional targets in Europe and Latin America; in 2016 a ransomware component was also incorporated into some KillDisk variants.
| Technique | Procedure example |
|---|---|
| T1027 Obfuscated Files or Information |
KillDisk uses VMProtect to make reverse engineering the malware more difficult. |
| T1036.004 Masquerade Task or Service |
KillDisk registers as a service under the Plug-And-Play Support name. |
| T1057 Process Discovery |
KillDisk has called |
| T1070.004 File Deletion |
KillDisk has the ability to quit and delete itself. |
| T1083 File and Directory Discovery |
KillDisk has used the |
| T1106 Native API |
KillDisk has called the Windows API to retrieve the hard disk handle and shut down the machine. |
| T1129 Shared Modules |
KillDisk loads and executes functions from a DLL. |
| T1134 Access Token Manipulation |
KillDisk has attempted to get the access token of a process by calling |
| T1485 Data Destruction |
KillDisk deletes system files to make the OS unbootable. KillDisk also targets and deletes files with 35 different file extensions. |
| T1486 Data Encrypted for Impact |
KillDisk has a ransomware component that encrypts files with an AES key that is also RSA-1028 encrypted. |
| T1489 Service Stop |
KillDisk terminates various processes to get the user to reboot the victim machine. |
| T1529 System Shutdown/Reboot |
KillDisk attempts to reboot the machine by terminating specific processes. |
| T1561.002 Disk Structure Wipe |
KillDisk overwrites the first sector of the Master Boot Record with “0x00”. |
| T1680 Local Storage Discovery |
KillDisk retrieves the hard disk name by calling the |
| T1685.005 Clear Windows Event Logs |
KillDisk deletes Application, Security, Setup, and System Windows Event Logs. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.