Disk Structure Wipe

T1561.002

Sub-technique of T1561 Disk Wipe.View on attack.mitre.org

About this technique

Adversaries may corrupt or wipe the disk data structures on a hard drive necessary to boot a system; targeting specific critical systems or in large numbers in a network to interrupt availability to system and network resources.

Adversaries may attempt to render the system unable to boot by overwriting critical data located in structures such as the master boot record (MBR) or partition table. The data contained in disk structures may include the initial executable code for loading an operating system or the location of the file system partitions on disk. If this information is not present, the computer will not be able to load an operating system during the boot process, leaving the computer unavailable. Disk Structure Wipe may be performed in isolation, or along with Disk Content Wipe if all sectors of a disk are wiped.

On a network devices, adversaries may reformat the file system using Network Device CLI commands such as `format`.

To maximize impact on the target organization, malware designed for destroying disk structures may have worm-like features to propagate across a network by leveraging other techniques like Valid Accounts, OS Credential Dumping, and SMB/Windows Admin Shares.

Detection rules3

Rules on DetectionCode tagged with T1561.002.

Sigma1

RuleLevelLog source
Cisco File Deletionmediumcisco / NULL

Splunk2

RuleTypeRiskData source
Windows Raw Access To Disk Volume PartitionAnomalyNULLSysmon EventID 9
Windows Raw Access To Master Boot Record DriveTTPNULLSysmon EventID 9

Groups6

Software13

Campaigns1

Procedure examples20

Groups6

Used byProcedure example
GroupAPT37

APT37 has access to destructive malware that is capable of overwriting a machine's Master Boot Record (MBR).

GroupAPT38

APT38 has used a custom MBR wiper named BOOTWRECK to render systems inoperable.

GroupEmber Bear

Ember Bear conducted destructive operations against victims, including disk structure wiping, via the WhisperGate malware in Ukraine.

GroupLazarus Group

Lazarus Group malware SHARPKNOT overwrites and deletes the Master Boot Record (MBR) on the victim's machine and has possessed MBR wiper malware since at least 2009.

GroupSandworm Team

Sandworm Team has used the BlackEnergy KillDisk component to corrupt the infected system's master boot record.

GroupVOID MANTICORE

VOID MANTICORE has deployed custom wipers that overwrite system files and the host devices master boot records (MBR) to corrupt or destroy files.

Software13

Used byProcedure example
MalwareBFG Agonizer

BFG Agonizer retrieves a device handle to \\\\.\\PhysicalDrive0 to wipe the boot sector of a given disk.

MalwareCaddyWiper

CaddyWiper has the ability to destroy information about a physical drive's partitions including the MBR, GPT, and partition entries.

MalwareDEADWOOD

DEADWOOD opens and writes zeroes to the first 512 bytes of each drive, deleting the MBR. DEADWOOD then sends the control code IOCTL_DISK_DELETE_DRIVE_LAYOUT to ensure the MBR is removed from the drive.

ToolDiskpart

Diskpart can be used to delete a partition or a volume. Diskpart can also be used to remove all partitions or volume formatting from the selected disk.

MalwareHermeticWiper

HermeticWiper has the ability to corrupt disk partitions, damage the Master Boot Record (MBR), and overwrite the Master File Table (MFT) of all available physical drives.

MalwareKillDisk

KillDisk overwrites the first sector of the Master Boot Record with “0x00”.

MalwareMultiLayer Wiper

MultiLayer Wiper opens a handle to \\\\\\\\.\\\\PhysicalDrive0 and wipes the first 512 bytes of data from this location, removing the boot sector.

ToolRawDisk

RawDisk was used in Shamoon to help overwrite components of disk structure like the MBR and disk partitions.

View all 13 software examples

Campaigns1

Used byProcedure example
CampaignHomeLand Justice

During HomeLand Justice, threat actors used a version of ZeroCleare to wipe disk drives on targeted hosts.

References6

  1. FireEye Shamoon Nov 2016 Open source
    FireEye. (2016, November 30). FireEye Responds to Wave of Destructive Cyber Attacks in Gulf Region. Retrieved November 17, 2024.
  2. Kaspersky StoneDrill 2017 Open source
    Kaspersky Lab. (2017, March 7). From Shamoon to StoneDrill: Wipers attacking Saudi organizations and beyond. Retrieved March 14, 2019.
  3. Palo Alto Shamoon Nov 2016 Open source
    Falcone, R.. (2016, November 30). Shamoon 2: Return of the Disttrack Wiper. Retrieved January 11, 2017.
  4. Symantec Shamoon 2012 Open source
    Symantec. (2012, August 16). The Shamoon Attacks. Retrieved March 14, 2019.
  5. Unit 42 Shamoon3 2018 Open source
    Falcone, R. (2018, December 13). Shamoon 3 Targets Oil and Gas Organization. Retrieved March 14, 2019.
  6. format_cmd_cisco Open source
    Cisco. (2022, August 16). format - Cisco IOS Configuration Fundamentals Command Reference. Retrieved July 13, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.