ATT&CKSoftwareMultiLayer Wiper

MultiLayer Wiper

S1135

Malware.View on attack.mitre.org

About this malware

MultiLayer Wiper is wiper malware written in .NET associated with Agrius operations. Observed samples of MultiLayer Wiper have an anomalous, future compilation date suggesting possible metadata manipulation.

Techniques used14

Procedure examples14

TechniqueProcedure example
T1027.009
Embedded Payloads

MultiLayer Wiper contains two binaries in its resources section, MultiList and MultiWip. MultiLayer Wiper drops and executes each of these items when run, then deletes them after execution.

T1053.005
Scheduled Task

MultiLayer Wiper creates a malicious scheduled task that launches a batch file to remove Windows Event Logs.

T1059.003
Windows Command Shell

MultiLayer Wiper uses a batch script launched via a scheduled task to delete Windows Event Logs.

T1070
Indicator Removal

MultiLayer Wiper uses a batch script to clear file system cache memory via the ProcessIdleTasks export in advapi32.dll as an anti-analysis and anti-forensics technique.

T1070.004
File Deletion

MultiLayer Wiper uses a batch file, remover.bat to delete malware artifacts and the batch file itself during execution.

T1070.006
Timestomp

MultiLayer Wiper changes timestamps of overwritten files to either 1601.1.1 for NTFS filesystems, or 1980.1.1 for all other filesystems.

T1083
File and Directory Discovery

MultiLayer Wiper generates a list of all files and paths on the fixed drives of an infected system, enumerating all files on the system except specific folders defined in a hardcoded list.

T1485
Data Destruction

MultiLayer Wiper deletes files on network drives, but corrupts and overwrites with random data files stored locally.

T1490
Inhibit System Recovery

MultiLayer Wiper wipes the boot sector of infected systems to inhibit system recovery.

T1529
System Shutdown/Reboot

MultiLayer Wiper reboots the infected system following wiping and related tasks to prevent system recovery.

T1561.002
Disk Structure Wipe

MultiLayer Wiper opens a handle to \\\\\\\\.\\\\PhysicalDrive0 and wipes the first 512 bytes of data from this location, removing the boot sector.

T1565.001
Stored Data Manipulation

MultiLayer Wiper changes the original path information of deleted files to make recovery efforts more difficult.

T1685
Disable or Modify Tools

MultiLayer Wiper removes the Volume Shadow Copy (VSS) service from infected devices along with all present shadow copies.

T1685.005
Clear Windows Event Logs

MultiLayer Wiper removes Windows event logs during execution.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Unit42 Agrius 2023 Open source
    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.