Malware.View on attack.mitre.org
BFG Agonizer is a wiper related to the open-source project CRYLINE-v.5.0. The malware is associated with wiping operations conducted by the Agrius threat actor.
| Technique | Procedure example |
|---|---|
| T1490 Inhibit System Recovery |
BFG Agonizer wipes the boot sector of infected machines to inhibit system recovery. |
| T1529 System Shutdown/Reboot |
BFG Agonizer uses elevated privileges to call |
| T1554 Compromise Host Software Binary |
BFG Agonizer uses DLL unhooking to remove user mode inline hooks that security solutions often implement. BFG Agonizer also uses IAT unhooking to remove user-mode IAT hooks that security solutions also use. |
| T1561.002 Disk Structure Wipe |
BFG Agonizer retrieves a device handle to |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.