ATT&CKSoftwareZeroCleare

ZeroCleare

S1151

Malware.View on attack.mitre.org

About this malware

ZeroCleare is a wiper malware that has been used in conjunction with the RawDisk driver since at least 2019 by suspected Iran-nexus threat actors including activity targeting the energy and industrial sectors in the Middle East and political targets in Albania.

Techniques used8

Procedure examples8

TechniqueProcedure example
T1059
Command and Scripting Interpreter

ZeroCleare can receive command line arguments from an operator to corrupt the file system using the RawDisk driver.

T1059.001
PowerShell

ZeroCleare can use a malicious PowerShell script to bypass Windows controls.

T1068
Exploitation for Privilege Escalation

ZeroCleare has used a vulnerable signed VBoxDrv driver to bypass Microsoft Driver Signature Enforcement (DSE) protections and subsequently load the unsigned RawDisk driver.

T1070.004
File Deletion

ZeroCleare has the ability to uninstall the RawDisk driver and delete the `rwdsk` file on disk.

T1106
Native API

ZeroCleare can call the `GetSystemDirectoryW` API to locate the system directory.

T1553.002
Code Signing

ZeroCleare can deploy a vulnerable, signed driver on a compromised host to bypass operating system safeguards.

T1561.002
Disk Structure Wipe

ZeroCleare can corrupt the file system and wipe the system drive on targeted hosts.

T1680
Local Storage Discovery

ZeroCleare can use the `IOCTL_DISK_GET_DRIVE_GEOMETRY_EX`, `IOCTL_DISK_GET_DRIVE_GEOMETRY`, and `IOCTL_DISK_GET_LENGTH_INFO` system calls to compute disk size.

Groups that use it1

Campaigns1

References4

  1. CISA Iran Albanian Attacks September 2022 Open source
    CISA. (2022, September 23). AA22-264A Iranian State Actors Conduct Cyber Operations Against the Government of Albania. Retrieved August 6, 2024.
  2. IBM ZeroCleare Wiper December 2019 Open source
    Kessem, L. (2019, December 4). New Destructive Wiper ZeroCleare Targets Energy Sector in the Middle East. Retrieved September 4, 2024.
  3. Mandiant ROADSWEEP August 2022 Open source
    Jenkins, L. at al. (2022, August 4). ROADSWEEP Ransomware - Likely Iranian Threat Actor Conducts Politically Motivated Disruptive Activity Against Albanian Government Organizations. Retrieved August 6, 2024.
  4. Microsoft Albanian Government Attacks September 2022 Open source
    MSTIC. (2022, September 8). Microsoft investigates Iranian attacks against the Albanian government. Retrieved August 6, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.