ATT&CKSoftwareBFG Agonizer

BFG Agonizer

S1136

Malware.View on attack.mitre.org

About this malware

BFG Agonizer is a wiper related to the open-source project CRYLINE-v.5.0. The malware is associated with wiping operations conducted by the Agrius threat actor.

Techniques used4

Procedure examples4

TechniqueProcedure example
T1490
Inhibit System Recovery

BFG Agonizer wipes the boot sector of infected machines to inhibit system recovery.

T1529
System Shutdown/Reboot

BFG Agonizer uses elevated privileges to call NtRaiseHardError to induce a "blue screen of death" on infected systems, causing a system crash. Once shut down, the system is no longer bootable.

T1554
Compromise Host Software Binary

BFG Agonizer uses DLL unhooking to remove user mode inline hooks that security solutions often implement. BFG Agonizer also uses IAT unhooking to remove user-mode IAT hooks that security solutions also use.

T1561.002
Disk Structure Wipe

BFG Agonizer retrieves a device handle to \\\\.\\PhysicalDrive0 to wipe the boot sector of a given disk.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Unit42 Agrius 2023 Open source
    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.