LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0607: KillDisk

KillDisk is a disk-wiping tool designed to overwrite files with random data to render the OS unbootable. It was first observed as a component of BlackEnergy malware during cyber attacks against Ukraine in 2015. KillDisk has since evolved into stand-alone malware used by a variety of threat actors against additional targets in Europe and Latin America; in 2016 a ransomware component was also incorporated into some KillDisk variants.[1][2][3][4]

EnterpriseS0607MalwareObject v1.2Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

KillDisk matters because it is destructive malware: its purpose is to overwrite files with random data and make operating systems unbootable. For leaders, this shifts the conversation from malware cleanup to business continuity, recovery readiness, and whether critical Windows and Linux systems can be restored fast enough after intentional destruction. Its ATT&CK relationships also connect it to ICS disruption, including the 2015 Ukraine Electric Power Attack, so organizations with operational technology dependencies should treat it as a resilience and incident-response planning issue, not only an endpoint alerting issue.

Executive priority

Prioritize validation of destructive-malware readiness: immutable or offline backups, tested bare-metal or critical-system recovery, privileged access control, segmentation between enterprise and operational environments, and evidence that SOC/IR teams can recognize pre-impact behaviors such as discovery, service stopping, file deletion, shutdown/reboot activity, and disk-structure wiping. The key business question is whether the organization can maintain or restore essential services if endpoints or operational support systems are rendered unbootable.

Technical view

ATT&CK lists KillDisk for Linux and Windows and relates it to destructive and impact behaviors including Data Destruction, Disk Structure Wipe, Data Encrypted for Impact, Service Stop, and System Shutdown/Reboot, plus discovery and stealth behaviors such as Process Discovery, File and Directory Discovery, Local Storage Discovery, File Deletion, Obfuscated Files or Information, Masquerade Task or Service, Native API, Shared Modules, and Access Token Manipulation. SOC teams should validate visibility across endpoint process execution, service control, filesystem changes, disk/volume access, reboot or shutdown commands, module loading, and privileged security-context changes. In ICS-adjacent environments, detection and response should also account for Loss of View and the possibility that host destruction can force manual operator intervention or impair operational visibility.

Likely telemetry

  • Endpoint process creation and command execution on Windows and Linux systems
  • Service creation, modification, stop, or disable events, including suspiciously named or masqueraded services/tasks
  • File deletion, high-volume overwrite, and abnormal filesystem activity
  • Disk, volume, boot structure, MBR, partition table, or raw device access telemetry where available
  • System shutdown and reboot events

Detection direction

  • Because ATT&CK provides no official detection text for KillDisk, build coverage from the related techniques rather than from a single malware signature.
  • Tune for behavior chains: discovery of processes/files/storage followed by service stops, destructive file or disk writes, file deletion, or shutdown/reboot activity.
  • Validate that alerts still reach the SOC if the affected host becomes unbootable; local-only logs are a major blind spot for destructive malware.
  • Hunt for suspicious task or service names that imitate legitimate services, especially when paired with destructive or recovery-inhibiting activity.
  • Separate legitimate administrative maintenance from suspicious activity using change windows, privileged user context, asset criticality, and whether actions occur across multiple systems.

Mitigation priorities

  • Start with recovery: maintain offline or immutable backups and regularly test restoration of critical Windows, Linux, and operational support systems.
  • Limit destructive reach by reducing standing administrative privileges and enforcing strong privileged-access workflows for systems that can affect availability.
  • Segment enterprise and operational environments so destructive activity on IT systems is less likely to impair ICS visibility or operations.
  • Harden and monitor critical services so unauthorized service stops, disables, or masqueraded services are detected and investigated quickly.
  • Centralize security logging off-host and protect telemetry pipelines from local file deletion or disk wiping.
Additional notes and limits

KillDisk is documented by ATT&CK as a disk-wiping tool first observed as part of BlackEnergy activity against Ukraine in 2015, later evolving into stand-alone malware used by multiple threat actors, with some variants incorporating a ransomware component. ATT&CK relationships associate it with the 2015 Ukraine Electric Power Attack, Sandworm Team, APT38, and multiple Enterprise and ICS techniques. These relationships justify focusing on destructive impact, recovery, and cyber-physical visibility risks, but local applicability depends on the organization’s platforms, exposure, and operational dependencies.

The supplied ATT&CK object has no official detection guidance and no listed tactics on the malware object itself. Technique relationships provide useful defensive direction, but they do not prove current exposure, active exploitation, or detection coverage in any specific environment. Platform assertions should be limited to the supplied KillDisk platforms, Linux and Windows, unless local evidence shows other affected systems.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

KillDisk

KillDisk is a disk-wiping tool designed to overwrite files with random data to render the OS unbootable. It was first observed as a component of BlackEnergy malware during cyber attacks against Ukraine in 2015. KillDisk has since evolved into stand-alone malware used by a variety of threat actors against additional targets in Europe and Latin America; in 2016 a ransomware component was also incorporated into some KillDisk variants.[1][2][3][4]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

15 rows
DomainIDNameRelationship / procedure
EnterpriseT1083File and Directory Discovery

KillDisk has used the FindNextFile command as part of its file deletion process.[4]

EnterpriseT1106Native API

KillDisk has called the Windows API to retrieve the hard disk handle and shut down the machine.[3]

EnterpriseT1680Local Storage Discovery

KillDisk retrieves the hard disk name by calling the CreateFileA to \\.\PHYSICALDRIVE0 API.[3]

EnterpriseT1129Shared Modules

KillDisk loads and executes functions from a DLL.[3]

EnterpriseT1057Process Discovery

KillDisk has called GetCurrentProcess.[4]

EnterpriseT1685.005Clear Windows Event LogsSub-technique

KillDisk deletes Application, Security, Setup, and System Windows Event Logs.[2]

EnterpriseT1027Obfuscated Files or Information

KillDisk uses VMProtect to make reverse engineering the malware more difficult.[3]

EnterpriseT1489Service Stop

KillDisk terminates various processes to get the user to reboot the victim machine.[4]

EnterpriseT1529System Shutdown/Reboot

KillDisk attempts to reboot the machine by terminating specific processes.[4]

EnterpriseT1561.002Disk Structure WipeSub-technique

KillDisk overwrites the first sector of the Master Boot Record with “0x00”.[3]

EnterpriseT1486Data Encrypted for Impact

KillDisk has a ransomware component that encrypts files with an AES key that is also RSA-1028 encrypted.[1]

EnterpriseT1070.004File DeletionSub-technique

KillDisk has the ability to quit and delete itself.[6]

EnterpriseT1036.004Masquerade Task or ServiceSub-technique

KillDisk registers as a service under the Plug-And-Play Support name.[6]

EnterpriseT1134Access Token Manipulation

KillDisk has attempted to get the access token of a process by calling OpenProcessToken. If KillDisk gets the access token, then it attempt to modify the token privileges with AdjustTokenPrivileges.[4]

EnterpriseT1485Data Destruction

KillDisk deletes system files to make the OS unbootable. KillDisk also targets and deletes files with 35 different file extensions.[2]

Associated objects

Groups, software, and campaigns

GroupEnterprise

G0082: APT38

APT38 is a North Korean state-sponsored threat group that specializes in financial cyber operations; it has been attributed to the Reconnaissance General Bureau.[1] Active since at least 2014, APT38 has targeted banks, financial institutions, casinos, cryptocurrency exchanges, SWIFT system endpoints, and ATMs in at least 38 countries worldwide. Significant operations include the 2016 Bank of Bangladesh heist, during which APT38 stole $81 million, as well as attacks against Bancomext [2] and Banco de Chile [2]; some of their attacks have been destructive.[1][2][3][4]

North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.

GroupEnterprise

G0034: Sandworm Team

Sandworm Team is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455.[1][2] This group has been active since at least 2009.[3][4][5][6]

In October 2020, the US indicted six GRU Unit 74455 officers associated with Sandworm Team for the following cyber operations: the 2015 and 2016 attacks against Ukrainian electrical companies and government organizations, the 2017 worldwide NotPetya attack, targeting of the 2017 French presidential campaign, the 2018 Olympic Destroyer attack against the Winter Olympic Games, the 2018 operation against the Organisation for the Prohibition of Chemical Weapons, and attacks against the country of Georgia in 2018 and 2019.[1][2] Some of these were conducted with the assistance of GRU Unit 26165, which is also referred to as APT28.[7]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.2
Created
Modified
Raw hash
89602566180874c5...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.2Current bundle896025661808…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    KillDisk Ransomware

    Catalin Cimpanu. (2016, December 29). KillDisk Disk-Wiping Malware Adds Ransomware Component. Retrieved January 12, 2021.

    Open source URL
  2. [2]
    ESEST Black Energy Jan 2016

    Cherepanov, A.. (2016, January 3). BlackEnergy by the SSHBearDoor: attacks against Ukrainian news media and electric industry. Retrieved May 18, 2016.

  3. [3]
    Trend Micro KillDisk 1

    Fernando Merces, Byron Gelera, Martin Co. (2018, June 7). KillDisk Variant Hits Latin American Finance Industry. Retrieved January 12, 2021.

    Open source URL
  4. [4]
    Trend Micro KillDisk 2

    Gilbert Sison, Rheniel Ramos, Jay Yaneza, Alfredo Oliveira. (2018, January 15). KillDisk Variant Hits Latin American Financial Groups. Retrieved January 12, 2021.

    Open source URL
  5. [5]
    Booz Allen Hamilton

    Booz Allen Hamilton. (2016). When The Lights Went Out. Retrieved December 18, 2024.

    Open source URL
  6. [6]
    ESET Telebots Dec 2016

    Cherepanov, A.. (2016, December 13). The rise of TeleBots: Analyzing disruptive KillDisk attacks. Retrieved June 10, 2020.

    Open source URL
  7. [7]
    ESET Lazarus KillDisk April 2018

    Kálnai, P., Cherepanov A. (2018, April 03). Lazarus KillDisks Central American casino. Retrieved May 17, 2018.

    Open source URL
  8. [8]
    US District Court Indictment GRU Unit 74455 October 2020

    Scott W. Brady. (2020, October 15). United States vs. Yuriy Sergeyevich Andrienko et al.. Retrieved November 25, 2020.

    Open source URL
  9. [9]
    Secureworks IRON VIKING

    Secureworks. (2020, May 1). IRON VIKING Threat Profile. Retrieved June 10, 2020.

    Open source URL
  10. [10]
    ESEST Black Energy Jan 2016

    Cherepanov, A.. (2016, January 3). BlackEnergy by the SSHBearDoor: attacks against Ukrainian news media and electric industry. Retrieved May 18, 2016.

  11. [11]
    ESEST Black Energy Jan 2016

    Cherepanov, A.. (2016, January 3). BlackEnergy by the SSHBearDoor: attacks against Ukrainian news media and electric industry. Retrieved May 18, 2016.

  12. [12]
    KillDisk Ransomware

    Catalin Cimpanu. (2016, December 29). KillDisk Disk-Wiping Malware Adds Ransomware Component. Retrieved January 12, 2021.

    Open source URL
  13. [13]
    KillDisk Ransomware

    Catalin Cimpanu. (2016, December 29). KillDisk Disk-Wiping Malware Adds Ransomware Component. Retrieved January 12, 2021.

    Open source URL
  14. [14]
    Trend Micro KillDisk 1

    Fernando Merces, Byron Gelera, Martin Co. (2018, June 7). KillDisk Variant Hits Latin American Finance Industry. Retrieved January 12, 2021.

    Open source URL
  15. [15]
    Trend Micro KillDisk 1

    Fernando Merces, Byron Gelera, Martin Co. (2018, June 7). KillDisk Variant Hits Latin American Finance Industry. Retrieved January 12, 2021.

    Open source URL
  16. [16]
    Trend Micro KillDisk 2

    Gilbert Sison, Rheniel Ramos, Jay Yaneza, Alfredo Oliveira. (2018, January 15). KillDisk Variant Hits Latin American Financial Groups. Retrieved January 12, 2021.

    Open source URL
  17. [17]
    Trend Micro KillDisk 2

    Gilbert Sison, Rheniel Ramos, Jay Yaneza, Alfredo Oliveira. (2018, January 15). KillDisk Variant Hits Latin American Financial Groups. Retrieved January 12, 2021.

    Open source URL
  18. [18]
    mitre-attackS0607
    Open source URL
  19. [19]
    mitre-attackS0607
    Open source URL
  20. [20]
    mitre-attackS0607
    Open source URL
  21. [21]
    Trend Micro KillDisk 2

    Gilbert Sison, Rheniel Ramos, Jay Yaneza, Alfredo Oliveira. (2018, January 15). KillDisk Variant Hits Latin American Financial Groups. Retrieved January 12, 2021.

    Open source URL
  22. [22]
    Trend Micro KillDisk 2

    Gilbert Sison, Rheniel Ramos, Jay Yaneza, Alfredo Oliveira. (2018, January 15). KillDisk Variant Hits Latin American Financial Groups. Retrieved January 12, 2021.

    Open source URL
  23. [23]
    Trend Micro KillDisk 1

    Fernando Merces, Byron Gelera, Martin Co. (2018, June 7). KillDisk Variant Hits Latin American Finance Industry. Retrieved January 12, 2021.

    Open source URL
  24. [24]
    Trend Micro KillDisk 1

    Fernando Merces, Byron Gelera, Martin Co. (2018, June 7). KillDisk Variant Hits Latin American Finance Industry. Retrieved January 12, 2021.

    Open source URL
  25. [25]
    Booz Allen Hamilton

    Booz Allen Hamilton. (2016). When The Lights Went Out. Retrieved December 18, 2024.

    Open source URL
  26. [26]
    Trend Micro KillDisk 1

    Fernando Merces, Byron Gelera, Martin Co. (2018, June 7). KillDisk Variant Hits Latin American Finance Industry. Retrieved January 12, 2021.

    Open source URL
  27. [27]
    Trend Micro KillDisk 1

    Fernando Merces, Byron Gelera, Martin Co. (2018, June 7). KillDisk Variant Hits Latin American Finance Industry. Retrieved January 12, 2021.

    Open source URL
  28. [28]
    Trend Micro KillDisk 1

    Fernando Merces, Byron Gelera, Martin Co. (2018, June 7). KillDisk Variant Hits Latin American Finance Industry. Retrieved January 12, 2021.

    Open source URL
  29. [29]
    Trend Micro KillDisk 1

    Fernando Merces, Byron Gelera, Martin Co. (2018, June 7). KillDisk Variant Hits Latin American Finance Industry. Retrieved January 12, 2021.

    Open source URL
  30. [30]
    Trend Micro KillDisk 2

    Gilbert Sison, Rheniel Ramos, Jay Yaneza, Alfredo Oliveira. (2018, January 15). KillDisk Variant Hits Latin American Financial Groups. Retrieved January 12, 2021.

    Open source URL
  31. [31]
    Trend Micro KillDisk 2

    Gilbert Sison, Rheniel Ramos, Jay Yaneza, Alfredo Oliveira. (2018, January 15). KillDisk Variant Hits Latin American Financial Groups. Retrieved January 12, 2021.

    Open source URL
  32. [32]
    ESEST Black Energy Jan 2016

    Cherepanov, A.. (2016, January 3). BlackEnergy by the SSHBearDoor: attacks against Ukrainian news media and electric industry. Retrieved May 18, 2016.

  33. [33]
    ESEST Black Energy Jan 2016

    Cherepanov, A.. (2016, January 3). BlackEnergy by the SSHBearDoor: attacks against Ukrainian news media and electric industry. Retrieved May 18, 2016.

  34. [34]
    Trend Micro KillDisk 1

    Fernando Merces, Byron Gelera, Martin Co. (2018, June 7). KillDisk Variant Hits Latin American Finance Industry. Retrieved January 12, 2021.

    Open source URL
  35. [35]
    Trend Micro KillDisk 1

    Fernando Merces, Byron Gelera, Martin Co. (2018, June 7). KillDisk Variant Hits Latin American Finance Industry. Retrieved January 12, 2021.

    Open source URL
  36. [36]
    Trend Micro KillDisk 2

    Gilbert Sison, Rheniel Ramos, Jay Yaneza, Alfredo Oliveira. (2018, January 15). KillDisk Variant Hits Latin American Financial Groups. Retrieved January 12, 2021.

    Open source URL
  37. [37]
    Trend Micro KillDisk 2

    Gilbert Sison, Rheniel Ramos, Jay Yaneza, Alfredo Oliveira. (2018, January 15). KillDisk Variant Hits Latin American Financial Groups. Retrieved January 12, 2021.

    Open source URL
  38. [38]
    Trend Micro KillDisk 2

    Gilbert Sison, Rheniel Ramos, Jay Yaneza, Alfredo Oliveira. (2018, January 15). KillDisk Variant Hits Latin American Financial Groups. Retrieved January 12, 2021.

    Open source URL
  39. [39]
    Trend Micro KillDisk 2

    Gilbert Sison, Rheniel Ramos, Jay Yaneza, Alfredo Oliveira. (2018, January 15). KillDisk Variant Hits Latin American Financial Groups. Retrieved January 12, 2021.

    Open source URL
  40. [40]
    Trend Micro KillDisk 1

    Fernando Merces, Byron Gelera, Martin Co. (2018, June 7). KillDisk Variant Hits Latin American Finance Industry. Retrieved January 12, 2021.

    Open source URL
  41. [41]
    Trend Micro KillDisk 1

    Fernando Merces, Byron Gelera, Martin Co. (2018, June 7). KillDisk Variant Hits Latin American Finance Industry. Retrieved January 12, 2021.

    Open source URL
  42. [42]
    KillDisk Ransomware

    Catalin Cimpanu. (2016, December 29). KillDisk Disk-Wiping Malware Adds Ransomware Component. Retrieved January 12, 2021.

    Open source URL
  43. [43]
    KillDisk Ransomware

    Catalin Cimpanu. (2016, December 29). KillDisk Disk-Wiping Malware Adds Ransomware Component. Retrieved January 12, 2021.

    Open source URL
  44. [44]
    ESET Telebots Dec 2016

    Cherepanov, A.. (2016, December 13). The rise of TeleBots: Analyzing disruptive KillDisk attacks. Retrieved June 10, 2020.

    Open source URL
  45. [45]
    ESET Lazarus KillDisk April 2018

    Kálnai, P., Cherepanov A. (2018, April 03). Lazarus KillDisks Central American casino. Retrieved May 17, 2018.

    Open source URL
  46. [46]
    ESET Telebots Dec 2016

    Cherepanov, A.. (2016, December 13). The rise of TeleBots: Analyzing disruptive KillDisk attacks. Retrieved June 10, 2020.

    Open source URL
  47. [47]
    ESET Telebots Dec 2016

    Cherepanov, A.. (2016, December 13). The rise of TeleBots: Analyzing disruptive KillDisk attacks. Retrieved June 10, 2020.

    Open source URL
  48. [48]
    Secureworks IRON VIKING

    Secureworks. (2020, May 1). IRON VIKING Threat Profile. Retrieved June 10, 2020.

    Open source URL
  49. [49]
    US District Court Indictment GRU Unit 74455 October 2020

    Scott W. Brady. (2020, October 15). United States vs. Yuriy Sergeyevich Andrienko et al.. Retrieved November 25, 2020.

    Open source URL
  50. [50]
    Trend Micro KillDisk 2

    Gilbert Sison, Rheniel Ramos, Jay Yaneza, Alfredo Oliveira. (2018, January 15). KillDisk Variant Hits Latin American Financial Groups. Retrieved January 12, 2021.

    Open source URL
  51. [51]
    Trend Micro KillDisk 2

    Gilbert Sison, Rheniel Ramos, Jay Yaneza, Alfredo Oliveira. (2018, January 15). KillDisk Variant Hits Latin American Financial Groups. Retrieved January 12, 2021.

    Open source URL
  52. [52]
    ESEST Black Energy Jan 2016

    Cherepanov, A.. (2016, January 3). BlackEnergy by the SSHBearDoor: attacks against Ukrainian news media and electric industry. Retrieved May 18, 2016.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.