Malware.View on attack.mitre.org
ZeroCleare is a wiper malware that has been used in conjunction with the RawDisk driver since at least 2019 by suspected Iran-nexus threat actors including activity targeting the energy and industrial sectors in the Middle East and political targets in Albania.
| Technique | Procedure example |
|---|---|
| T1059 Command and Scripting Interpreter |
ZeroCleare can receive command line arguments from an operator to corrupt the file system using the RawDisk driver. |
| T1059.001 PowerShell |
ZeroCleare can use a malicious PowerShell script to bypass Windows controls. |
| T1068 Exploitation for Privilege Escalation |
ZeroCleare has used a vulnerable signed VBoxDrv driver to bypass Microsoft Driver Signature Enforcement (DSE) protections and subsequently load the unsigned RawDisk driver. |
| T1070.004 File Deletion |
ZeroCleare has the ability to uninstall the RawDisk driver and delete the `rwdsk` file on disk. |
| T1106 Native API |
ZeroCleare can call the `GetSystemDirectoryW` API to locate the system directory. |
| T1553.002 Code Signing |
ZeroCleare can deploy a vulnerable, signed driver on a compromised host to bypass operating system safeguards. |
| T1561.002 Disk Structure Wipe |
ZeroCleare can corrupt the file system and wipe the system drive on targeted hosts. |
| T1680 Local Storage Discovery |
ZeroCleare can use the `IOCTL_DISK_GET_DRIVE_GEOMETRY_EX`, `IOCTL_DISK_GET_DRIVE_GEOMETRY`, and `IOCTL_DISK_GET_LENGTH_INFO` system calls to compute disk size. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.