ATT&CKSoftwareCaddyWiper

CaddyWiper

S0693

Malware.View on attack.mitre.org

About this malware

CaddyWiper is a destructive data wiper that has been used in attacks against organizations in Ukraine since at least March 2022.

Techniques used7

Procedure examples7

TechniqueProcedure example
T1057
Process Discovery

CaddyWiper can obtain a list of current processes.

T1082
System Information Discovery

CaddyWiper can use `DsRoleGetPrimaryDomainInformation` to determine the role of the infected machine. CaddyWiper can also halt execution if the compromised host is identified as a domain controller.

T1083
File and Directory Discovery

CaddyWiper can enumerate all files and directories on a compromised host.

T1106
Native API

CaddyWiper has the ability to dynamically resolve and use APIs, including `SeTakeOwnershipPrivilege`.

T1222.001
Windows Permissions

CaddyWiper can modify ACL entries to take ownership of files.

T1485
Data Destruction

CaddyWiper can work alphabetically through drives on a compromised system to take ownership of and overwrite all files.

T1561.002
Disk Structure Wipe

CaddyWiper has the ability to destroy information about a physical drive's partitions including the MBR, GPT, and partition entries.

Groups that use it0

None recorded.

Campaigns1

References2

  1. Cisco CaddyWiper March 2022 Open source
    Malhotra, A. (2022, March 15). Threat Advisory: CaddyWiper. Retrieved March 23, 2022.
  2. ESET CaddyWiper March 2022 Open source
    ESET. (2022, March 15). CaddyWiper: New wiper malware discovered in Ukraine. Retrieved March 23, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.