Malware.View on attack.mitre.org
HermeticWiper is a data wiper that has been used since at least early 2022, primarily against Ukraine with additional activity observed in Latvia and Lithuania. Some sectors targeted include government, financial, defense, aviation, and IT services.
| Technique | Procedure example |
|---|---|
| T1027.015 Compression |
HermeticWiper can compress 32-bit and 64-bit driver files with the Lempel-Ziv algorithm. |
| T1036.005 Match Legitimate Resource Name or Location |
HermeticWiper has used the name `postgressql.exe` to mask a malicious payload. |
| T1053.005 Scheduled Task |
HermeticWiper has the ability to use scheduled tasks for execution. |
| T1059.003 Windows Command Shell |
HermeticWiper can use `cmd.exe /Q/c move CSIDL_SYSTEM_DRIVE\temp\sys.tmp1 CSIDL_WINDOWS\policydefinitions\postgresql.exe 1> \\127.0.0.1\ADMIN$\_1636727589.6007507 2>&1` to deploy on an infected system. |
| T1070 Indicator Removal |
HermeticWiper can disable pop-up information about folders and desktop items and delete Registry keys to hide malicious services. |
| T1070.004 File Deletion |
HermeticWiper has the ability to overwrite its own file with random bites. |
| T1082 System Information Discovery |
HermeticWiper can determine the OS version and bitness on a targeted host. |
| T1083 File and Directory Discovery |
HermeticWiper can enumerate common folders such as My Documents, Desktop, and AppData. |
| T1106 Native API |
HermeticWiper can call multiple Windows API functions used for privilege escalation, service execution, and to overwrite random bites of data. |
| T1112 Modify Registry |
HermeticWiper has the ability to modify Registry keys to disable crash dumps, colors for compressed files, and pop-up information about folders and desktop items. |
| T1134 Access Token Manipulation |
HermeticWiper can use `AdjustTokenPrivileges` to grant itself privileges for debugging with `SeDebugPrivilege`, creating backups with `SeBackupPrivilege`, loading drivers with `SeLoadDriverPrivilege`, and shutting down a local system with `SeShutdownPrivilege`. |
| T1140 Deobfuscate/Decode Files or Information |
HermeticWiper can decompress and copy driver files using `LZCopy`. |
| T1484.001 Group Policy Modification |
HermeticWiper has the ability to deploy through an infected system's default domain policy. |
| T1485 Data Destruction |
HermeticWiper can recursively wipe folders and files in `Windows`, `Program Files`, `Program Files(x86)`, `PerfLogs`, `Boot, System`, `Volume Information`, and `AppData` folders using `FSCTL_MOVE_FILE`. HermeticWiper can also overwrite symbolic links and big files in `My Documents` and on the Desktop with random bytes. |
| T1489 Service Stop |
HermeticWiper has the ability to stop the Volume Shadow Copy service. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.