Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1560.003 Archive via Custom Method |
MalwareDuqu | Modules can be pushed to and executed by Duqu that copy data to a staging area, compress it, and XOR encrypt it. |
| T1561.001 Disk Content Wipe |
CampaignAPT28 Nearest Neighbor Campaign | During APT28 Nearest Neighbor Campaign, APT28 used the native Microsoft utility cipher.exe to securely wipe files and folders – overwriting the deleted data using |
| T1561.001 Disk Content Wipe |
GroupGamaredon Group | Gamaredon Group has used tools to delete files and folders from victims' desktops and profiles. |
| T1561.001 Disk Content Wipe |
GroupLazarus Group | Lazarus Group has used malware like WhiskeyAlfa to overwrite the first 64MB of every drive with a mix of static and random buffers. A similar process is then used to wipe content in logical drives and, finally, attempt to wipe every byte of every sector on every drive. WhiskeyBravo can be used to overwrite the first 4.9MB of physical drives. WhiskeyDelta can overwrite the first 132MB or 1.5MB of each drive with random data from heap memory. |
| T1561.001 Disk Content Wipe |
GroupVOID MANTICORE | VOID MANTICORE has utilized a disk wiping utility to facilitate destructive actions on victim servers. VOID MANTICORE has also utilized legitimate remote disk wiping commands. |
| T1561.001 Disk Content Wipe |
MalwareAcidRain | AcidRain iterates over device file identifiers on the target, opens the device file, and either overwrites the file or calls various IOCTLS commands to erase it. |
| T1561.001 Disk Content Wipe |
MalwareApostle | Apostle searches for files on available drives based on a list of extensions hard-coded into the sample for follow-on wipe activity. |
| T1561.001 Disk Content Wipe |
MalwareWhisperGate | WhisperGate can overwrite sectors of a victim host's hard drive at periodic offsets. |
| T1561.001 Disk Content Wipe |
MalwareAcidPour | AcidPour includes functionality to overwrite victim devices with the content of a buffer to wipe disk content. |
| T1561.001 Disk Content Wipe |
MalwareBlackCat | BlackCat has the ability to wipe VM snapshots on compromised networks. |
| T1561.001 Disk Content Wipe |
MalwareVPNFilter | VPNFilter has the capability to wipe a portion of an infected device's firmware. |
| T1561.001 Disk Content Wipe |
MalwareDarkGate | DarkGate has deleted all files in the Mozilla directory using the following command: `/c del /q /f /s C:\Users\User\AppData\Roaming\Mozilla\firefox*`. |
| T1561.001 Disk Content Wipe |
MalwareStoneDrill | StoneDrill can wipe the accessible physical or logical drives of the infected machine. |
| T1561.001 Disk Content Wipe |
MalwareMegaCortex | MegaCortex can wipe deleted data from all drives using |
| T1561.001 Disk Content Wipe |
MalwareHermeticWiper | HermeticWiper has the ability to corrupt disk partitions and obtain raw disk access to destroy data. |
| T1561.001 Disk Content Wipe |
MalwareDEADWOOD | DEADWOOD deletes files following overwriting them with random data. |
| T1561.001 Disk Content Wipe |
ToolRawDisk | RawDisk has been used to directly access the hard disk to help overwrite arbitrarily sized portions of disk content. |
| T1561.001 Disk Content Wipe |
Toolcipher.exe | cipher.exe can be used to overwrite deleted data in specified folders. |
| T1561.002 Disk Structure Wipe |
CampaignHomeLand Justice | During HomeLand Justice, threat actors used a version of ZeroCleare to wipe disk drives on targeted hosts. |
| T1561.002 Disk Structure Wipe |
GroupAPT38 | APT38 has used a custom MBR wiper named BOOTWRECK to render systems inoperable. |
| T1561.002 Disk Structure Wipe |
GroupSandworm Team | Sandworm Team has used the BlackEnergy KillDisk component to corrupt the infected system's master boot record. |
| T1561.002 Disk Structure Wipe |
GroupAPT37 | APT37 has access to destructive malware that is capable of overwriting a machine's Master Boot Record (MBR). |
| T1561.002 Disk Structure Wipe |
GroupEmber Bear | Ember Bear conducted destructive operations against victims, including disk structure wiping, via the WhisperGate malware in Ukraine. |
| T1561.002 Disk Structure Wipe |
GroupLazarus Group | Lazarus Group malware SHARPKNOT overwrites and deletes the Master Boot Record (MBR) on the victim's machine and has possessed MBR wiper malware since at least 2009. |
| T1561.002 Disk Structure Wipe |
GroupVOID MANTICORE | VOID MANTICORE has deployed custom wipers that overwrite system files and the host devices master boot records (MBR) to corrupt or destroy files. |
| T1561.002 Disk Structure Wipe |
MalwareShrinkLocker | ShrinkLocker has used Diskpart to format newly-created partitions. |
| T1561.002 Disk Structure Wipe |
MalwareWhisperGate | WhisperGate can overwrite the Master Book Record (MBR) on victim systems with a malicious 16-bit bootloader. |
| T1561.002 Disk Structure Wipe |
MalwareMultiLayer Wiper | MultiLayer Wiper opens a handle to |
| T1561.002 Disk Structure Wipe |
MalwareShamoon | Shamoon has been seen overwriting features of disk structure such as the MBR. |
| T1561.002 Disk Structure Wipe |
MalwareStoneDrill | StoneDrill can wipe the master boot record of an infected computer. |
| T1561.002 Disk Structure Wipe |
MalwareHermeticWiper | HermeticWiper has the ability to corrupt disk partitions, damage the Master Boot Record (MBR), and overwrite the Master File Table (MFT) of all available physical drives. |
| T1561.002 Disk Structure Wipe |
MalwareCaddyWiper | CaddyWiper has the ability to destroy information about a physical drive's partitions including the MBR, GPT, and partition entries. |
| T1561.002 Disk Structure Wipe |
MalwareBFG Agonizer | BFG Agonizer retrieves a device handle to |
| T1561.002 Disk Structure Wipe |
MalwareKillDisk | KillDisk overwrites the first sector of the Master Boot Record with “0x00”. |
| T1561.002 Disk Structure Wipe |
MalwareDEADWOOD | DEADWOOD opens and writes zeroes to the first 512 bytes of each drive, deleting the MBR. DEADWOOD then sends the control code |
| T1561.002 Disk Structure Wipe |
ToolDiskpart | Diskpart can be used to delete a partition or a volume. Diskpart can also be used to remove all partitions or volume formatting from the selected disk. |
| T1561.002 Disk Structure Wipe |
ToolRawDisk | RawDisk was used in Shamoon to help overwrite components of disk structure like the MBR and disk partitions. |
| T1561.002 Disk Structure Wipe |
MalwareZeroCleare | ZeroCleare can corrupt the file system and wipe the system drive on targeted hosts. |
| T1563.001 SSH Hijacking |
MalwareMEDUSA | MEDUSA can be configured to capture SSH credentials via SSH hijacking. |
| T1563.002 RDP Hijacking |
GroupAxiom | Axiom has targeted victims with remote administration tools including RDP. |
| T1563.002 RDP Hijacking |
MalwareWannaCry | WannaCry enumerates current remote desktop sessions and tries to execute the malware on each session. |
| T1564 Hide Artifacts |
MalwareDarkTortilla | DarkTortilla has used `%HiddenReg%` and `%HiddenKey%` as part of its persistence via the Windows registry. |
| T1564 Hide Artifacts |
MalwareNOOPLDR | NOOPLDR can hide services used to aid execution. |
| T1564 Hide Artifacts |
MalwareBundlore | Bundlore uses the |
| T1564 Hide Artifacts |
MalwareTarrask | Tarrask is able to create “hidden” scheduled tasks by deleting the Security Descriptor (`SD`) registry value. |
| T1564 Hide Artifacts |
MalwareOSX/Shlayer | OSX/Shlayer has used the |
| T1564 Hide Artifacts |
MalwareWarzoneRAT | WarzoneRAT can masquerade the Process Environment Block on a compromised host to hide its attempts to elevate privileges through `IFileOperation`. |
| T1564 Hide Artifacts |
ToolRemcos | Remcos can modify file attributes to hide the file. |
| T1564.001 Hidden Files and Directories |
CampaignRedDelta Modified PlugX Infection Chain Operations | Mustang Panda stored encrypted payloads associated with PlugX installation in hidden directories during RedDelta Modified PlugX Infection Chain Operations. |
| T1564.001 Hidden Files and Directories |
GroupAPT32 | APT32's macOS backdoor hides the clientID file via a chflags function. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.