Malware.View on attack.mitre.org
Meteor is a wiper that was used against Iranian government organizations, including Iranian Railways, the Ministry of Roads, and Urban Development systems, in July 2021. Meteor is likely a newer version of similar wipers called Stardust and Comet that were reportedly used by a group called "Indra" since at least 2019 against private companies in Syria.
| Technique | Procedure example |
|---|---|
| T1036.004 Masquerade Task or Service |
Meteor has been disguised as the Windows Power Efficiency Diagnostics report tool. |
| T1047 Windows Management Instrumentation |
Meteor can use `wmic.exe` as part of its effort to delete shadow copies. |
| T1053.005 Scheduled Task |
Meteor execution begins from a scheduled task named `Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeAll` and it creates a separate scheduled task called `mstask` to run the wiper only once at 23:55:00. |
| T1057 Process Discovery |
Meteor can check if a specific process is running, such as Kaspersky's `avp.exe`. |
| T1059.001 PowerShell |
Meteor can use PowerShell commands to disable the network adapters on a victim machines. |
| T1059.003 Windows Command Shell |
Meteor can run `set.bat`, `update.bat`, `cache.bat`, `bcd.bat`, `msrun.bat`, and similar scripts. |
| T1070.004 File Deletion |
Meteor will delete the folder containing malicious scripts if it detects the hostname as `PIS-APP`, `PIS-MOB`, `WSUSPROXY`, or `PIS-DB`. |
| T1082 System Information Discovery |
Meteor has the ability to discover the hostname of a compromised host. |
| T1105 Ingress Tool Transfer |
Meteor has the ability to download additional files for execution on the victim's machine. |
| T1106 Native API |
Meteor can use `WinAPI` to remove a victim machine from an Active Directory domain. |
| T1484.001 Group Policy Modification |
Meteor can use group policy to push a scheduled task from the AD to all network machines. |
| T1485 Data Destruction |
Meteor can fill a victim's files and directories with zero-bytes in replacement of real content before deleting them. |
| T1489 Service Stop |
Meteor can disconnect all network adapters on a compromised host using `powershell -Command "Get-WmiObject -class Win32_NetworkAdapter | ForEach { If ($.NetEnabled) { $.Disable() } }" > NUL`. |
| T1490 Inhibit System Recovery |
Meteor can use `bcdedit` to delete different boot identifiers on a compromised host; it can also use `vssadmin.exe delete shadows /all /quiet` and `C:\\Windows\\system32\\wbem\\wmic.exe shadowcopy delete`. |
| T1491.001 Internal Defacement |
Meteor can change both the desktop wallpaper and the lock screen image to a custom image. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.