Sub-technique of T1561 Disk Wipe.View on attack.mitre.org
Adversaries may corrupt or wipe the disk data structures on a hard drive necessary to boot a system; targeting specific critical systems or in large numbers in a network to interrupt availability to system and network resources.
Adversaries may attempt to render the system unable to boot by overwriting critical data located in structures such as the master boot record (MBR) or partition table. The data contained in disk structures may include the initial executable code for loading an operating system or the location of the file system partitions on disk. If this information is not present, the computer will not be able to load an operating system during the boot process, leaving the computer unavailable. Disk Structure Wipe may be performed in isolation, or along with Disk Content Wipe if all sectors of a disk are wiped.
On a network devices, adversaries may reformat the file system using Network Device CLI commands such as `format`.
To maximize impact on the target organization, malware designed for destroying disk structures may have worm-like features to propagate across a network by leveraging other techniques like Valid Accounts, OS Credential Dumping, and SMB/Windows Admin Shares.
Rules on DetectionCode tagged with T1561.002.
| Rule | Level | Log source |
|---|---|---|
| Cisco File Deletion | medium | cisco / NULL |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Windows Raw Access To Disk Volume Partition | Anomaly | NULL | Sysmon EventID 9 |
| Windows Raw Access To Master Boot Record Drive | TTP | NULL | Sysmon EventID 9 |
| Used by | Procedure example |
|---|---|
| GroupAPT37 | APT37 has access to destructive malware that is capable of overwriting a machine's Master Boot Record (MBR). |
| GroupAPT38 | APT38 has used a custom MBR wiper named BOOTWRECK to render systems inoperable. |
| GroupEmber Bear | Ember Bear conducted destructive operations against victims, including disk structure wiping, via the WhisperGate malware in Ukraine. |
| GroupLazarus Group | Lazarus Group malware SHARPKNOT overwrites and deletes the Master Boot Record (MBR) on the victim's machine and has possessed MBR wiper malware since at least 2009. |
| GroupSandworm Team | Sandworm Team has used the BlackEnergy KillDisk component to corrupt the infected system's master boot record. |
| GroupVOID MANTICORE | VOID MANTICORE has deployed custom wipers that overwrite system files and the host devices master boot records (MBR) to corrupt or destroy files. |
| Used by | Procedure example |
|---|---|
| MalwareBFG Agonizer | BFG Agonizer retrieves a device handle to |
| MalwareCaddyWiper | CaddyWiper has the ability to destroy information about a physical drive's partitions including the MBR, GPT, and partition entries. |
| MalwareDEADWOOD | DEADWOOD opens and writes zeroes to the first 512 bytes of each drive, deleting the MBR. DEADWOOD then sends the control code |
| ToolDiskpart | Diskpart can be used to delete a partition or a volume. Diskpart can also be used to remove all partitions or volume formatting from the selected disk. |
| MalwareHermeticWiper | HermeticWiper has the ability to corrupt disk partitions, damage the Master Boot Record (MBR), and overwrite the Master File Table (MFT) of all available physical drives. |
| MalwareKillDisk | KillDisk overwrites the first sector of the Master Boot Record with “0x00”. |
| MalwareMultiLayer Wiper | MultiLayer Wiper opens a handle to |
| ToolRawDisk | RawDisk was used in Shamoon to help overwrite components of disk structure like the MBR and disk partitions. |
| Used by | Procedure example |
|---|---|
| CampaignHomeLand Justice | During HomeLand Justice, threat actors used a version of ZeroCleare to wipe disk drives on targeted hosts. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.