Meteor

S0688

Malware.View on attack.mitre.org

About this malware

Meteor is a wiper that was used against Iranian government organizations, including Iranian Railways, the Ministry of Roads, and Urban Development systems, in July 2021. Meteor is likely a newer version of similar wipers called Stardust and Comet that were reportedly used by a group called "Indra" since at least 2019 against private companies in Syria.

Techniques used20

Procedure examples20

TechniqueProcedure example
T1036.004
Masquerade Task or Service

Meteor has been disguised as the Windows Power Efficiency Diagnostics report tool.

T1047
Windows Management Instrumentation

Meteor can use `wmic.exe` as part of its effort to delete shadow copies.

T1053.005
Scheduled Task

Meteor execution begins from a scheduled task named `Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeAll` and it creates a separate scheduled task called `mstask` to run the wiper only once at 23:55:00.

T1057
Process Discovery

Meteor can check if a specific process is running, such as Kaspersky's `avp.exe`.

T1059.001
PowerShell

Meteor can use PowerShell commands to disable the network adapters on a victim machines.

T1059.003
Windows Command Shell

Meteor can run `set.bat`, `update.bat`, `cache.bat`, `bcd.bat`, `msrun.bat`, and similar scripts.

T1070.004
File Deletion

Meteor will delete the folder containing malicious scripts if it detects the hostname as `PIS-APP`, `PIS-MOB`, `WSUSPROXY`, or `PIS-DB`.

T1082
System Information Discovery

Meteor has the ability to discover the hostname of a compromised host.

T1105
Ingress Tool Transfer

Meteor has the ability to download additional files for execution on the victim's machine.

T1106
Native API

Meteor can use `WinAPI` to remove a victim machine from an Active Directory domain.

T1484.001
Group Policy Modification

Meteor can use group policy to push a scheduled task from the AD to all network machines.

T1485
Data Destruction

Meteor can fill a victim's files and directories with zero-bytes in replacement of real content before deleting them.

T1489
Service Stop

Meteor can disconnect all network adapters on a compromised host using `powershell -Command "Get-WmiObject -class Win32_NetworkAdapter | ForEach { If ($.NetEnabled) { $.Disable() } }" > NUL`.

T1490
Inhibit System Recovery

Meteor can use `bcdedit` to delete different boot identifiers on a compromised host; it can also use `vssadmin.exe delete shadows /all /quiet` and `C:\\Windows\\system32\\wbem\\wmic.exe shadowcopy delete`.

T1491.001
Internal Defacement

Meteor can change both the desktop wallpaper and the lock screen image to a custom image.

View all 20 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. Check Point Meteor Aug 2021 Open source
    Check Point Research Team. (2021, August 14). Indra - Hackers Behind Recent Attacks on Iran. Retrieved February 17, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.