Data Destruction

T1485

Technique with 1 sub-technique.View on attack.mitre.org

About this technique

Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and remote drives. Common operating system file deletion commands such as del and rm often only remove pointers to files without wiping the contents of the files themselves, making the files recoverable by proper forensic methodology. This behavior is distinct from Disk Content Wipe and Disk Structure Wipe because individual files are destroyed rather than sections of a storage disk or the disk's logical structure.

Adversaries may attempt to overwrite files and directories with randomly generated data to make it irrecoverable. In some cases politically oriented image files have been used to overwrite data.

To maximize impact on the target organization in operations where network-wide availability interruption is the goal, malware designed for destroying data may have worm-like features to propagate across a network by leveraging additional techniques like Valid Accounts, OS Credential Dumping, and SMB/Windows Admin Shares..

In cloud environments, adversaries may leverage access to delete cloud storage objects, machine images, database instances, and other infrastructure crucial to operations to damage an organization or their customers. Similarly, they may delete virtual machines from on-prem virtualized environments.

Detection rules57

Rules on DetectionCode tagged with T1485 or one of its sub-techniques.

Sigma19

Splunk38

RuleTypeRiskData sourceTechnique
ASL AWS Defense Evasion PutBucketLifecycleHuntingNULLASL AWS CloudTrailT1485.001
AWS Bedrock Delete Knowledge BaseTTPNULLAWS CloudTrail DeleteKnowledgeBaseT1485
AWS Defense Evasion PutBucketLifecycleHuntingNULLAWS CloudTrail PutBucketLifecycleT1485.001
Common Ransomware ExtensionsTTPNULLSysmon EventID 11T1485
Common Ransomware NotesHuntingNULLSysmon EventID 11T1485
Detect DNS Query to Decommissioned S3 BucketAnomalyNULLSysmon EventID 22T1485
Detect Web Access to Decommissioned S3 BucketAnomalyNULLAWS CloudfrontT1485
Excessive File Deletion In WinDefender FolderTTPNULLSysmon EventID 23, Sysmon EventID 26T1485
GitHub Enterprise Remove OrganizationAnomalyNULLGitHub Enterprise Audit LogsT1485
GitHub Enterprise Repository ArchivedAnomalyNULLGitHub Enterprise Audit LogsT1485
GitHub Enterprise Repository DeletedAnomalyNULLGitHub Enterprise Audit LogsT1485
GitHub Organizations Repository ArchivedAnomalyNULLGitHub Organizations Audit LogsT1485
GitHub Organizations Repository DeletedAnomalyNULLGitHub Organizations Audit LogsT1485
Linux Account Manipulation Of SSH Config and KeysAnomalyNULLSysmon for Linux EventID 11T1485
Linux Auditd Data Destruction CommandTTPNULLLinux Auditd ProctitleT1485

Sub-techniques1

IDNameExamples
T1485.001Lifecycle-Triggered Deletion0

Groups8

Software30

Show 6 more

Campaigns2

Procedure examples40

Groups8

Used byProcedure example
GroupAPT38

APT38 has used a custom secure delete function to make deleted files unrecoverable.

GroupLAPSUS$

LAPSUS$ has deleted the target's systems and resources both on-premises and in the cloud.

GroupLazarus Group

Lazarus Group has used a custom secure delete function to overwrite file contents with data from heap memory.

GroupSandworm Team

Sandworm Team has used CaddyWiper, SDelete, and the BlackEnergy KillDisk component to overwrite files on victim systems. Additionally, Sandworm Team has used the JUNKMAIL tool to overwrite files with null bytes.

GroupShinyHunters

ShinyHunters has executed the `DeleteBucket` API call to delete buckets.

GroupStorm-0501

Storm-0501 has destroyed data and backup files.

GroupTeamPCP

TeamPCP has deployed privileged DaemonSets to delete files on Kubernetes clusters and has executed recursive file deletions on non-containerized hosts.

GroupVOID MANTICORE

VOID MANTICORE has conducted data wiping attacks on compromised systems. VOID MANTICORE has also manually deleted files from compromised hosts, to include selecting all files and then deleting them.

Software30

Used byProcedure example
MalwareAcidPour

AcidPour can perform an in-depth wipe of victim filesystems and attached storage devices through either data overwrite or calling various IOCTLS to erase them, similar to AcidRain.

MalwareAcidRain

AcidRain performs an in-depth wipe of the target filesystem and various attached storage devices through either a data overwrite or calling various IOCTLS to erase it.

MalwareApostle

Apostle initially masqueraded as ransomware but actual functionality is a data destruction tool, supported by an internal name linked to an early version, wiper-action. Apostle writes random data to original files after an encrypted copy is created, along with resizing the original file to zero and changing time property metadata before finally deleting the original file.

MalwareBlackEnergy

BlackEnergy 2 contains a "Destroy" plug-in that destroys data stored on victim hard drives by overwriting file contents.

MalwareCaddyWiper

CaddyWiper can work alphabetically through drives on a compromised system to take ownership of and overwrite all files.

MalwareCanisterWorm

CanisterWorm has targeted wiper components that can delete entire clusters and execute recursive file deletions on non-containerized hosts.

MalwareDEADWOOD

DEADWOOD overwrites files on victim systems with random data to effectively destroy them.

MalwareDiavol

Diavol can delete specified files from a targeted system.

View all 30 software examples

Campaigns2

Used byProcedure example
Campaign2022 Ukraine Electric Power Attack

During the 2022 Ukraine Electric Power Attack, Sandworm Team deployed CaddyWiper on the victim’s IT environment systems to wipe files related to the OT capabilities, along with mapped drives, and physical drive partitions.

Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries utilized wiper malware to overwrite files using a 16-byte buffer that fully overwrites files 16 bytes or smaller or partially overwrites files greater than 16 bytes to speed up the process.

References8

  1. DOJ - Cisco Insider Open source
    DOJ. (2020, August 26). San Jose Man Pleads Guilty To Damaging Cisco’s Network. Retrieved December 15, 2020.
  2. Data Destruction - Threat Post Open source
    Mimoso, M.. (2014, June 18). Hacker Puts Hosting Service Code Spaces Out of Business. Retrieved December 15, 2020.
  3. FireEye Shamoon Nov 2016 Open source
    FireEye. (2016, November 30). FireEye Responds to Wave of Destructive Cyber Attacks in Gulf Region. Retrieved November 17, 2024.
  4. Kaspersky StoneDrill 2017 Open source
    Kaspersky Lab. (2017, March 7). From Shamoon to StoneDrill: Wipers attacking Saudi organizations and beyond. Retrieved March 14, 2019.
  5. Palo Alto Shamoon Nov 2016 Open source
    Falcone, R.. (2016, November 30). Shamoon 2: Return of the Disttrack Wiper. Retrieved January 11, 2017.
  6. Symantec Shamoon 2012 Open source
    Symantec. (2012, August 16). The Shamoon Attacks. Retrieved March 14, 2019.
  7. Talos Olympic Destroyer 2018 Open source
    Mercer, W. and Rascagneres, P. (2018, February 12). Olympic Destroyer Takes Aim At Winter Olympics. Retrieved March 14, 2019.
  8. Unit 42 Shamoon3 2018 Open source
    Falcone, R. (2018, December 13). Shamoon 3 Targets Oil and Gas Organization. Retrieved March 14, 2019.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.