LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1561.002: Disk Structure Wipe

Adversaries may corrupt or wipe the disk data structures on a hard drive necessary to boot a system; targeting specific critical systems or in large numbers in a network to interrupt availability to system and network resources.

Adversaries may attempt to render the system unable to boot by overwriting critical data located in structures such as the master boot record (MBR) or partition table.[1][2][3][4][5] The data contained in disk structures may include the initial executable code for loading an operating system or the location of the file system partitions on disk. If this information is not present, the computer will not be able to load an operating system during the boot process, leaving the computer unavailable. Disk Structure Wipe may be performed in isolation, or along with Disk Content Wipe if all sectors of a disk are wiped.

On a network devices, adversaries may reformat the file system using Network Device CLI commands such as `format`.[6]

To maximize impact on the target organization, malware designed for destroying disk structures may have worm-like features to propagate across a network by leveraging other techniques like Valid Accounts, OS Credential Dumping, and SMB/Windows Admin Shares.[1][2][3][4]

EnterpriseT1561.002Sub-techniqueObject v1.2Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Disk Structure Wipe is a destructive impact behavior aimed at making systems unbootable by corrupting critical disk structures such as the master boot record or partition table. For leaders, the key issue is not data theft; it is operational availability. If this occurs on servers, endpoints, or network devices, recovery may depend on whether the organization can rebuild systems and restore from protected backups quickly enough to sustain business operations.

Executive priority

Treat this as a resilience and incident-readiness priority for critical systems. The supplied ATT&CK context links the technique to destructive campaigns, wiper malware, and propagation paths that may involve valid accounts, credential dumping, and SMB/Windows admin shares. Executives should ask whether backup isolation, recovery testing, privileged access controls, and SOC escalation procedures are sufficient for a destructive event where systems may no longer boot. For network devices, confirm whether administrative command use such as file-system formatting is logged and governed.

Technical view

This is an impact sub-technique of Disk Wipe across Linux, macOS, Windows, and network devices. SOC and IR teams should validate visibility for direct modification of boot or partition structures, suspicious use of disk-management utilities or drivers, and destructive administrative commands on network devices. Relationship context identifies DET0297, Detection Strategy for Disk Structure Wipe via Boot/Partition Overwrite, as relevant, and M1053 Data Backup as the mapped mitigation. Because ATT&CK provides no official detection text for this object, teams should rely on local telemetry validation, known-good administrative baselines, and incident response playbooks for rapid containment and restoration.

Likely telemetry

  • Endpoint process execution involving disk, partition, boot, or volume management utilities, including Windows Diskpart where present in the supplied relationships
  • Kernel, driver, or raw disk access telemetry, especially activity resembling direct modification of disks or partitions such as use of RawDisk-like capability
  • File integrity or low-level disk monitoring for changes to boot records, partition tables, or other structures required for boot
  • Windows, Linux, and macOS security and system logs that show privileged storage-management activity
  • Network device administrative logs and CLI command history for file-system formatting commands such as format

Detection direction

  • Validate whether DET0297-style logic for boot or partition overwrite is implemented, tested, and mapped to the platforms in scope.
  • Tune detections around rare or high-risk disk structure changes, but account for legitimate administrative tasks such as imaging, disk replacement, partitioning, or network device maintenance.
  • Correlate destructive disk activity with preceding signs of propagation or privilege use, including valid account activity, credential dumping context, and SMB/Windows admin share access where those data sources exist.
  • For network devices, monitor and review administrative commands capable of reformatting file systems; absence of centralized device command logging is a material blind spot.
  • Prioritize high-confidence escalation over noisy standalone alerts, because this technique can rapidly convert a security incident into an availability crisis.

Mitigation priorities

  • Prioritize M1053 Data Backup: maintain regular, secure, isolated backups for critical servers and end-user systems, and test restoration for unbootable-system scenarios.
  • Harden backup systems and keep backup storage separated from the corporate network so destructive activity cannot easily affect recovery points during an active incident.
  • Reduce the chance of large-scale wipe propagation by tightening privileged account use and monitoring, especially where valid accounts, credential dumping, and SMB/Windows admin shares could enable spread.
  • Restrict and monitor administrative access to disk-management functions and network device commands capable of formatting storage.
  • Maintain incident response procedures for destructive malware events, including rapid isolation, rebuild paths, and business continuity decision points for critical services.
Additional notes and limits

The relationship set shows this technique used by multiple named groups, campaigns, and wiper-related software, including Shamoon, StoneDrill, KillDisk, WhisperGate, CaddyWiper, HermeticWiper, ZeroCleare, and others. Use those relationships for threat-informed prioritization, not as evidence that any specific organization is currently targeted. The older T1487 object is revoked by this sub-technique, so reporting and detection engineering should reference T1561.002.

ATT&CK provides no official detection text for this object, so detection guidance must be validated against local logging, endpoint controls, network device administration records, and backup architecture. The supplied fields support platforms and relationships, but they do not establish active exploitation, customer exposure, or guaranteed detection coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Disk Structure Wipe

Adversaries may corrupt or wipe the disk data structures on a hard drive necessary to boot a system; targeting specific critical systems or in large numbers in a network to interrupt availability to system and network resources.

Adversaries may attempt to render the system unable to boot by overwriting critical data located in structures such as the master boot record (MBR) or partition table.[1][2][3][4][5] The data contained in disk structures may include the initial executable code for loading an operating system or the location of the file system partitions on disk. If this information is not present, the computer will not be able to load an operating system during the boot process, leaving the computer unavailable. Disk Structure Wipe may be performed in isolation, or along with Disk Content Wipe if all sectors of a disk are wiped.

On a network devices, adversaries may reformat the file system using Network Device CLI commands such as `format`.[6]

To maximize impact on the target organization, malware designed for destroying disk structures may have worm-like features to propagate across a network by leveraging other techniques like Valid Accounts, OS Credential Dumping, and SMB/Windows Admin Shares.[1][2][3][4]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Related techniques

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

2 rows
DomainIDNameRelationship / procedure
EnterpriseT1561Disk WipeThis object subtechnique of Disk Wipe.
EnterpriseT1487Disk Structure WipeDisk Structure Wipe revoked by this object.
Associated objects

Groups, software, and campaigns

GroupEnterprise

G1055: VOID MANTICORE

VOID MANTICORE is a threat group assessed to operate on behalf of Iran’s Ministry of Intelligence and Security (MOIS).[1] Active since at least mid-2022, VOID MANTICORE has targeted government entities, critical infrastructure, and private sector organizations across Albania, Israel, and the United States.[1][2] VOID MANTICORE conducts destructive cyber operations, combining wiper attacks with hack-and-leak campaigns. The group has operated under multiple public-facing personas, including HomeLand Justice in operations against Albania, Karma and Karma Below in campaigns targeting Israeli organizations, and Handala Hack, its current primary persona, which has claimed activity against Israeli and U.S. entities, including a March 2026 attack against Stryker Corporation.[1][3] VOID MANTICORE has been observed collaborating with Scarred Manticore, which has been linked to initial access operations preceding VOID MANTICORE’s activity.[4]

GroupEnterprise

G0082: APT38

APT38 is a North Korean state-sponsored threat group that specializes in financial cyber operations; it has been attributed to the Reconnaissance General Bureau.[1] Active since at least 2014, APT38 has targeted banks, financial institutions, casinos, cryptocurrency exchanges, SWIFT system endpoints, and ATMs in at least 38 countries worldwide. Significant operations include the 2016 Bank of Bangladesh heist, during which APT38 stole $81 million, as well as attacks against Bancomext [2] and Banco de Chile [2]; some of their attacks have been destructive.[1][2][3][4]

North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.

GroupEnterprise

G0034: Sandworm Team

Sandworm Team is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455.[1][2] This group has been active since at least 2009.[3][4][5][6]

In October 2020, the US indicted six GRU Unit 74455 officers associated with Sandworm Team for the following cyber operations: the 2015 and 2016 attacks against Ukrainian electrical companies and government organizations, the 2017 worldwide NotPetya attack, targeting of the 2017 French presidential campaign, the 2018 Olympic Destroyer attack against the Winter Olympic Games, the 2018 operation against the Organisation for the Prohibition of Chemical Weapons, and attacks against the country of Georgia in 2018 and 2019.[1][2] Some of these were conducted with the assistance of GRU Unit 26165, which is also referred to as APT28.[7]

GroupEnterprise

G0032: Lazarus Group

Lazarus Group is a North Korean state-sponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). [1] [2] Lazarus Group has been active since at least 2009 and is reportedly responsible for the November 2014 destructive wiper attack on Sony Pictures Entertainment, identified by Novetta as part of Operation Blockbuster. Malware used by Lazarus Group correlates to other reported campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain.[3]

North Korea’s cyber operations have shown a consistent pattern of adaptation, forming and reorganizing units as national priorities shift. These units frequently share personnel, infrastructure, malware, and tradecraft, making it difficult to attribute specific operations with high confidence. Public reporting often uses “Lazarus Group” as an umbrella term for multiple North Korean cyber operators conducting espionage, destructive attacks, and financially motivated campaigns.[4][5][6]

GroupEnterprise

G1003: Ember Bear

Ember Bear is a Russian state-sponsored cyber espionage group that has been active since at least 2020, linked to Russia's General Staff Main Intelligence Directorate (GRU) 161st Specialist Training Center (Unit 29155).[1] Ember Bear has primarily focused operations against Ukrainian government and telecommunication entities, but has also operated against critical infrastructure entities in Europe and the Americas.[2] Ember Bear conducted the WhisperGate destructive wiper attacks against Ukraine in early 2022.[3][4][1] There is some confusion as to whether Ember Bear overlaps with another Russian-linked entity referred to as Saint Bear. At present available evidence strongly suggests these are distinct activities with different behavioral profiles.[2][5]

GroupEnterprise

G0067: APT37

APT37 is a North Korean state-sponsored cyber espionage group that has been active since at least 2012. The group has targeted victims primarily in South Korea, but also in Japan, Vietnam, Russia, Nepal, China, India, Romania, Kuwait, and other parts of the Middle East. APT37 has also been linked to the following campaigns between 2016-2018: Operation Daybreak, Operation Erebus, Golden Time, Evil New Year, Are you Happy?, FreeMilk, North Korean Human Rights, and Evil New Year 2018.[1][2][3]

North Korean group definitions are known to have significant overlap, and some security researchers report all North Korean state-sponsored cyber activity under the name Lazarus Group instead of tracking clusters or subgroups.

MalwareEnterprise

S0140: Shamoon

Shamoon is wiper malware that was first used by an Iranian group known as the "Cutting Sword of Justice" in 2012. Other versions known as Shamoon 2 and Shamoon 3 were observed in 2016 and 2018. Shamoon has also been seen leveraging RawDisk and Filerase to carry out data wiping tasks. Analysis has linked Shamoon with Kwampirs based on multiple shared artifacts and coding patterns.[1] The term Shamoon is sometimes used to refer to the group using the malware as well as the malware itself.[2][3][4][5]

Windows
ToolEnterprise

S9002: Diskpart

Diskpart is a Windows command-line utility that is used to manage the computer’s drives, which includes disks, partitions, volumes and virtual hard disks.[1]

Adversaries may abuse Diskpart to perform discovery and destructive actions on a system’s storage. For example, adversaries have been observed using Diskpart to conduct Discovery techniques to enumerate disks and volumes to gather information about the host environment, and to execute commands such as `clean all` to remove partition information and overwrite data across disks, resulting in data destruction.[2]

Windows
MalwareEnterprise

S0697: HermeticWiper

HermeticWiper is a data wiper that has been used since at least early 2022, primarily against Ukraine with additional activity observed in Latvia and Lithuania. Some sectors targeted include government, financial, defense, aviation, and IT services.[1][2][3][4][5]

Windows
ToolEnterprise

S0364: RawDisk

RawDisk is a legitimate commercial driver from the EldoS Corporation that is used for interacting with files, disks, and partitions. The driver allows for direct modification of data on a local computer's hard drive. In some cases, the tool can enact these raw disk modifications from user-mode processes, circumventing Windows operating system security features.[1][2]

Windows
MalwareEnterprise

S0689: WhisperGate

WhisperGate is a multi-stage wiper designed to look like ransomware that has been used against multiple government, non-profit, and information technology organizations in Ukraine since at least January 2022.[1][2][3]

Windows
MalwareEnterprise

S1178: ShrinkLocker

ShrinkLocker is a VBS-based malicious script that leverages the legitimate Bitlocker application to encrypt files on victim systems for ransom. ShrinkLocker functions by using Bitlocker to encrypt files, then renames impacted drives to the adversary’s contact email address to facilitate communication for the ransom payment.[1][2]

Windows
MalwareEnterprise

S0607: KillDisk

KillDisk is a disk-wiping tool designed to overwrite files with random data to render the OS unbootable. It was first observed as a component of BlackEnergy malware during cyber attacks against Ukraine in 2015. KillDisk has since evolved into stand-alone malware used by a variety of threat actors against additional targets in Europe and Latin America; in 2016 a ransomware component was also incorporated into some KillDisk variants.[1][2][3][4]

LinuxWindows
MalwareEnterprise

S1134: DEADWOOD

DEADWOOD is wiper malware written in C++ using Boost libraries. DEADWOOD was first observed in an unattributed wiping event in Saudi Arabia in 2019, and has since been incorporated into Agrius operations.[1]

Windows
MalwareEnterprise

S1151: ZeroCleare

ZeroCleare is a wiper malware that has been used in conjunction with the RawDisk driver since at least 2019 by suspected Iran-nexus threat actors including activity targeting the energy and industrial sectors in the Middle East and political targets in Albania.[1][2][3][4]

Windows
CampaignEnterprise

C0038: HomeLand Justice

HomeLand Justice was a disruptive cyber campaign conducted by Iranian state-affiliated actors against Albanian government networks in July and September 2022. The activity combined ransomware, wiper malware, and data leak operations. Initial access for HomeLand Justice was established as early as May 2021, and threat actors moved laterally, exfiltrated sensitive information, and maintained persistence for approximately 14 months prior to the destructive phase of the operation. Responsibility was claimed by the "HomeLand Justice" front, which framed the campaign as retaliation against the Mujahedeen-e Khalq (MEK), an Iranian opposition group with a presence in Albania. Multiple Iran-nexus groups are assessed to have participated in the campaign, including HEXANE who probed victim infrastructure.[1][2][3] A second wave of attacks was launched in September 2022 using similar tactics following public attribution of the previous activity to Iran and the severing of diplomatic ties between Iran and Albania.[3]

Relationship explorer

All related ATT&CK context

Mitigations

Mitigation direction

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.2
Created
Modified
Raw hash
f4fc7211b7c29927...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.2Current bundlef4fc7211b7c2…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Symantec Shamoon 2012

    Symantec. (2012, August 16). The Shamoon Attacks. Retrieved March 14, 2019.

    Open source URL
  2. [2]
    FireEye Shamoon Nov 2016

    FireEye. (2016, November 30). FireEye Responds to Wave of Destructive Cyber Attacks in Gulf Region. Retrieved November 17, 2024.

    Open source URL
  3. [3]
    Palo Alto Shamoon Nov 2016

    Falcone, R.. (2016, November 30). Shamoon 2: Return of the Disttrack Wiper. Retrieved January 11, 2017.

  4. [4]
    Kaspersky StoneDrill 2017

    Kaspersky Lab. (2017, March 7). From Shamoon to StoneDrill: Wipers attacking Saudi organizations and beyond. Retrieved March 14, 2019.

    Open source URL
  5. [5]
    Unit 42 Shamoon3 2018

    Falcone, R. (2018, December 13). Shamoon 3 Targets Oil and Gas Organization. Retrieved March 14, 2019.

    Open source URL
  6. [6]
    format_cmd_cisco

    Cisco. (2022, August 16). format - Cisco IOS Configuration Fundamentals Command Reference. Retrieved July 13, 2022.

    Open source URL
  7. [7]
    Microsoft_diskpart_Feb2023

    Microsoft. (2023, February 3). diskpart. Retrieved March 17, 2025.

    Open source URL
  8. [8]
    Trendmicro_RansomHub_Dec2024

    Trend Research. (2024, December 20). RansomHub. Retrieved December 23, 2025.

    Open source URL
  9. [9]
    CISA Iran Albanian Attacks September 2022

    CISA. (2022, September 23). AA22-264A Iranian State Actors Conduct Cyber Operations Against the Government of Albania. Retrieved August 6, 2024.

    Open source URL
  10. [10]
    Microsoft Albanian Government Attacks September 2022

    MSTIC. (2022, September 8). Microsoft investigates Iranian attacks against the Albanian government. Retrieved August 6, 2024.

    Open source URL
  11. [11]
    SentinelOne Hermetic Wiper February 2022

    Guerrero-Saade, J. (2022, February 23). HermeticWiper | New Destructive Malware Used In Cyber Attacks on Ukraine. Retrieved March 25, 2022.

    Open source URL
  12. [12]
    Symantec Ukraine Wipers February 2022

    Symantec Threat Hunter Team. (2022, February 24). Ukraine: Disk-wiping Attacks Precede Russian Invasion. Retrieved March 25, 2022.

    Open source URL
  13. [13]
    Crowdstrike DriveSlayer February 2022

    Thomas, W. et al. (2022, February 25). CrowdStrike Falcon Protects from New Wiper Malware Used in Ukraine Cyberattacks. Retrieved March 25, 2022.

    Open source URL
  14. [14]
    Qualys Hermetic Wiper March 2022

    Dani, M. (2022, March 1). Ukrainian Targets Hit by HermeticWiper, New Datawiper Malware. Retrieved March 25, 2022.

    Open source URL
  15. [15]
    Unit42 Agrius 2023

    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

    Open source URL
  16. [16]
    Microsoft WhisperGate January 2022

    MSTIC. (2022, January 15). Destructive malware targeting Ukrainian organizations. Retrieved March 10, 2022.

    Open source URL
  17. [17]
    Crowdstrike WhisperGate January 2022

    Crowdstrike. (2022, January 19). Technical Analysis of the WhisperGate Malicious Bootloader. Retrieved March 10, 2022.

    Open source URL
  18. [18]
    Cybereason WhisperGate February 2022

    Cybereason Nocturnus. (2022, February 15). Cybereason vs. WhisperGate and HermeticWiper. Retrieved March 10, 2022.

    Open source URL
  19. [19]
    Unit 42 WhisperGate January 2022

    Falcone, R. et al.. (2022, January 20). Threat Brief: Ongoing Russia and Ukraine Cyber Conflict. Retrieved March 10, 2022.

    Open source URL
  20. [20]
    Cisco Ukraine Wipers January 2022

    Biasini, N. et al.. (2022, January 21). Ukraine Campaign Delivers Defacement and Wipers, in Continued Escalation. Retrieved March 14, 2022.

    Open source URL
  21. [21]
    Medium S2W WhisperGate January 2022

    S2W. (2022, January 18). Analysis of Destructive Malware (WhisperGate) targeting Ukraine. Retrieved March 14, 2022.

    Open source URL
  22. [22]
    Splunk ShrinkLocker 2024

    Splunk Threat Research Team , Teoderick Contreras. (2024, September 5). ShrinkLocker Malware: Abusing BitLocker to Lock Your Data. Retrieved December 7, 2024.

    Open source URL
  23. [23]
    Check Point VOID MANTICORE Handala Hack March 2026

    Check Point Research. (2026, March 12). “Handala Hack” – Unveiling Group’s Modus Operandi. Retrieved April 20, 2026.

    Open source URL
  24. [24]
    FireEye APT38 Oct 2018

    FireEye. (2018, October 03). APT38: Un-usual Suspects. Retrieved November 17, 2024.

    Open source URL
  25. [25]
    US-CERT Ukraine Feb 2016

    US-CERT. (2016, February 25). ICS Alert (IR-ALERT-H-16-056-01) Cyber-Attack Against Ukrainian Critical Infrastructure. Retrieved June 10, 2020.

    Open source URL
  26. [26]
    ESET Telebots June 2017

    Cherepanov, A.. (2017, June 30). TeleBots are back: Supply chain attacks against Ukraine. Retrieved June 11, 2020.

    Open source URL
  27. [27]
    US-CERT SHARPKNOT June 2018

    US-CERT. (2018, March 09). Malware Analysis Report (MAR) - 10135536.11.WHITE. Retrieved June 13, 2018.

    Open source URL
  28. [28]
    Novetta Blockbuster

    Novetta Threat Research Group. (2016, February 24). Operation Blockbuster: Unraveling the Long Thread of the Sony Attack. Retrieved February 25, 2016.

    Open source URL
  29. [29]
    Trend Micro KillDisk 1

    Fernando Merces, Byron Gelera, Martin Co. (2018, June 7). KillDisk Variant Hits Latin American Finance Industry. Retrieved January 12, 2021.

    Open source URL
  30. [30]
    Symantec Elfin Mar 2019

    Security Response attack Investigation Team. (2019, March 27). Elfin: Relentless Espionage Group Targets Multiple Organizations in Saudi Arabia and U.S.. Retrieved April 10, 2019.

    Open source URL
  31. [31]
    Cadet Blizzard emerges as novel threat actor

    Microsoft Threat Intelligence. (2023, June 14). Cadet Blizzard emerges as a novel and distinct Russian threat actor. Retrieved July 10, 2023.

    Open source URL
  32. [32]
    Ready.gov IT DRP

    Ready.gov. (n.d.). IT Disaster Recovery Plan. Retrieved March 15, 2019.

    Open source URL
  33. [33]
    SentinelOne Agrius 2021

    Amitai Ben & Shushan Ehrlich. (2021, May). From Wiper to Ransomware: The Evolution of Agrius. Retrieved May 21, 2024.

    Open source URL
  34. [34]
    Mandiant ROADSWEEP August 2022

    Jenkins, L. at al. (2022, August 4). ROADSWEEP Ransomware - Likely Iranian Threat Actor Conducts Politically Motivated Disruptive Activity Against Albanian Government Organizations. Retrieved August 6, 2024.

    Open source URL
  35. [35]
    IBM ZeroCleare Wiper December 2019

    Kessem, L. (2019, December 4). New Destructive Wiper ZeroCleare Targets Energy Sector in the Middle East. Retrieved September 4, 2024.

    Open source URL
  36. [36]
    ESET CaddyWiper March 2022

    ESET. (2022, March 15). CaddyWiper: New wiper malware discovered in Ukraine. Retrieved March 23, 2022.

    Open source URL
  37. [37]
    Cisco CaddyWiper March 2022

    Malhotra, A. (2022, March 15). Threat Advisory: CaddyWiper. Retrieved March 23, 2022.

    Open source URL
  38. [38]
    FireEye APT37 Feb 2018

    FireEye. (2018, February 20). APT37 (Reaper): The Overlooked North Korean Actor. Retrieved November 17, 2024.

    Open source URL
  39. [39]
    Talos Group123

    Mercer, W., Rascagneres, P. (2018, January 16). Korea In The Crosshairs. Retrieved May 21, 2018.

    Open source URL
  40. [40]
    FireEye Shamoon Nov 2016

    FireEye. (2016, November 30). FireEye Responds to Wave of Destructive Cyber Attacks in Gulf Region. Retrieved November 17, 2024.

    Open source URL
  41. [41]
    FireEye Shamoon Nov 2016

    FireEye. (2016, November 30). FireEye Responds to Wave of Destructive Cyber Attacks in Gulf Region. Retrieved November 17, 2024.

    Open source URL
  42. [42]
    Kaspersky StoneDrill 2017

    Kaspersky Lab. (2017, March 7). From Shamoon to StoneDrill: Wipers attacking Saudi organizations and beyond. Retrieved March 14, 2019.

    Open source URL
  43. [43]
    Kaspersky StoneDrill 2017

    Kaspersky Lab. (2017, March 7). From Shamoon to StoneDrill: Wipers attacking Saudi organizations and beyond. Retrieved March 14, 2019.

    Open source URL
  44. [44]
    Microsoft Sysmon v6 May 2017

    Russinovich, M. & Garnier, T. (2017, May 22). Sysmon v6.20. Retrieved December 13, 2017.

    Open source URL
  45. [45]
    Microsoft Sysmon v6 May 2017

    Russinovich, M. & Garnier, T. (2017, May 22). Sysmon v6.20. Retrieved December 13, 2017.

    Open source URL
  46. [46]
    Microsoft Sysmon v6 May 2017

    Russinovich, M. & Garnier, T. (2017, May 22). Sysmon v6.20. Retrieved December 13, 2017.

    Open source URL
  47. [47]
    Palo Alto Shamoon Nov 2016

    Falcone, R.. (2016, November 30). Shamoon 2: Return of the Disttrack Wiper. Retrieved January 11, 2017.

  48. [48]
    Palo Alto Shamoon Nov 2016

    Falcone, R.. (2016, November 30). Shamoon 2: Return of the Disttrack Wiper. Retrieved January 11, 2017.

  49. [49]
    Symantec Shamoon 2012

    Symantec. (2012, August 16). The Shamoon Attacks. Retrieved March 14, 2019.

    Open source URL
  50. [50]
    Symantec Shamoon 2012

    Symantec. (2012, August 16). The Shamoon Attacks. Retrieved March 14, 2019.

    Open source URL
  51. [51]
    Unit 42 Shamoon3 2018

    Falcone, R. (2018, December 13). Shamoon 3 Targets Oil and Gas Organization. Retrieved March 14, 2019.

    Open source URL
  52. [52]
    Unit 42 Shamoon3 2018

    Falcone, R. (2018, December 13). Shamoon 3 Targets Oil and Gas Organization. Retrieved March 14, 2019.

    Open source URL
  53. [53]
    format_cmd_cisco

    Cisco. (2022, August 16). format - Cisco IOS Configuration Fundamentals Command Reference. Retrieved July 13, 2022.

    Open source URL
  54. [54]
    format_cmd_cisco

    Cisco. (2022, August 16). format - Cisco IOS Configuration Fundamentals Command Reference. Retrieved July 13, 2022.

    Open source URL
  55. [55]
    mitre-attackT1561.002
    Open source URL
  56. [56]
    mitre-attackT1561.002
    Open source URL
  57. [57]
    mitre-attackT1561.002
    Open source URL
  58. [58]
    FireEye Shamoon Nov 2016

    FireEye. (2016, November 30). FireEye Responds to Wave of Destructive Cyber Attacks in Gulf Region. Retrieved November 17, 2024.

    Open source URL
  59. [59]
    FireEye Shamoon Nov 2016

    FireEye. (2016, November 30). FireEye Responds to Wave of Destructive Cyber Attacks in Gulf Region. Retrieved November 17, 2024.

    Open source URL
  60. [60]
    Palo Alto Shamoon Nov 2016

    Falcone, R.. (2016, November 30). Shamoon 2: Return of the Disttrack Wiper. Retrieved January 11, 2017.

  61. [61]
    Palo Alto Shamoon Nov 2016

    Falcone, R.. (2016, November 30). Shamoon 2: Return of the Disttrack Wiper. Retrieved January 11, 2017.

  62. [62]
    Symantec Shamoon 2012

    Symantec. (2012, August 16). The Shamoon Attacks. Retrieved March 14, 2019.

    Open source URL
  63. [63]
    Symantec Shamoon 2012

    Symantec. (2012, August 16). The Shamoon Attacks. Retrieved March 14, 2019.

    Open source URL
  64. [64]
    Unit 42 Shamoon3 2018

    Falcone, R. (2018, December 13). Shamoon 3 Targets Oil and Gas Organization. Retrieved March 14, 2019.

    Open source URL
  65. [65]
    Unit 42 Shamoon3 2018

    Falcone, R. (2018, December 13). Shamoon 3 Targets Oil and Gas Organization. Retrieved March 14, 2019.

    Open source URL
  66. [66]
    Microsoft_diskpart_Feb2023

    Microsoft. (2023, February 3). diskpart. Retrieved March 17, 2025.

    Open source URL
  67. [67]
    Trendmicro_RansomHub_Dec2024

    Trend Research. (2024, December 20). RansomHub. Retrieved December 23, 2025.

    Open source URL
  68. [68]
    CISA Iran Albanian Attacks September 2022

    CISA. (2022, September 23). AA22-264A Iranian State Actors Conduct Cyber Operations Against the Government of Albania. Retrieved August 6, 2024.

    Open source URL
  69. [69]
    Microsoft Albanian Government Attacks September 2022

    MSTIC. (2022, September 8). Microsoft investigates Iranian attacks against the Albanian government. Retrieved August 6, 2024.

    Open source URL
  70. [70]
    Crowdstrike DriveSlayer February 2022

    Thomas, W. et al. (2022, February 25). CrowdStrike Falcon Protects from New Wiper Malware Used in Ukraine Cyberattacks. Retrieved March 25, 2022.

    Open source URL
  71. [71]
    Qualys Hermetic Wiper March 2022

    Dani, M. (2022, March 1). Ukrainian Targets Hit by HermeticWiper, New Datawiper Malware. Retrieved March 25, 2022.

    Open source URL
  72. [72]
    SentinelOne Hermetic Wiper February 2022

    Guerrero-Saade, J. (2022, February 23). HermeticWiper | New Destructive Malware Used In Cyber Attacks on Ukraine. Retrieved March 25, 2022.

    Open source URL
  73. [73]
    Symantec Ukraine Wipers February 2022

    Symantec Threat Hunter Team. (2022, February 24). Ukraine: Disk-wiping Attacks Precede Russian Invasion. Retrieved March 25, 2022.

    Open source URL
  74. [74]
    Palo Alto Shamoon Nov 2016

    Falcone, R.. (2016, November 30). Shamoon 2: Return of the Disttrack Wiper. Retrieved January 11, 2017.

  75. [75]
    Palo Alto Shamoon Nov 2016

    Falcone, R.. (2016, November 30). Shamoon 2: Return of the Disttrack Wiper. Retrieved January 11, 2017.

  76. [76]
    Unit 42 Shamoon3 2018

    Falcone, R. (2018, December 13). Shamoon 3 Targets Oil and Gas Organization. Retrieved March 14, 2019.

    Open source URL
  77. [77]
    Unit 42 Shamoon3 2018

    Falcone, R. (2018, December 13). Shamoon 3 Targets Oil and Gas Organization. Retrieved March 14, 2019.

    Open source URL
  78. [78]
    Unit42 Agrius 2023

    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

    Open source URL
  79. [79]
    Cisco Ukraine Wipers January 2022

    Biasini, N. et al.. (2022, January 21). Ukraine Campaign Delivers Defacement and Wipers, in Continued Escalation. Retrieved March 14, 2022.

    Open source URL
  80. [80]
    Crowdstrike WhisperGate January 2022

    Crowdstrike. (2022, January 19). Technical Analysis of the WhisperGate Malicious Bootloader. Retrieved March 10, 2022.

    Open source URL
  81. [81]
    Cybereason WhisperGate February 2022

    Cybereason Nocturnus. (2022, February 15). Cybereason vs. WhisperGate and HermeticWiper. Retrieved March 10, 2022.

    Open source URL
  82. [82]
    Medium S2W WhisperGate January 2022

    S2W. (2022, January 18). Analysis of Destructive Malware (WhisperGate) targeting Ukraine. Retrieved March 14, 2022.

    Open source URL
  83. [83]
    Microsoft WhisperGate January 2022

    MSTIC. (2022, January 15). Destructive malware targeting Ukrainian organizations. Retrieved March 10, 2022.

    Open source URL
  84. [84]
    Unit 42 WhisperGate January 2022

    Falcone, R. et al.. (2022, January 20). Threat Brief: Ongoing Russia and Ukraine Cyber Conflict. Retrieved March 10, 2022.

    Open source URL
  85. [85]
    Splunk ShrinkLocker 2024

    Splunk Threat Research Team , Teoderick Contreras. (2024, September 5). ShrinkLocker Malware: Abusing BitLocker to Lock Your Data. Retrieved December 7, 2024.

    Open source URL
  86. [86]
    Check Point VOID MANTICORE Handala Hack March 2026

    Check Point Research. (2026, March 12). “Handala Hack” – Unveiling Group’s Modus Operandi. Retrieved April 20, 2026.

    Open source URL
  87. [87]
    FireEye APT38 Oct 2018

    FireEye. (2018, October 03). APT38: Un-usual Suspects. Retrieved November 17, 2024.

    Open source URL
  88. [88]
    ESET Telebots June 2017

    Cherepanov, A.. (2017, June 30). TeleBots are back: Supply chain attacks against Ukraine. Retrieved June 11, 2020.

    Open source URL
  89. [89]
    US-CERT Ukraine Feb 2016

    US-CERT. (2016, February 25). ICS Alert (IR-ALERT-H-16-056-01) Cyber-Attack Against Ukrainian Critical Infrastructure. Retrieved June 10, 2020.

    Open source URL
  90. [90]
    Novetta Blockbuster

    Novetta Threat Research Group. (2016, February 24). Operation Blockbuster: Unraveling the Long Thread of the Sony Attack. Retrieved February 25, 2016.

    Open source URL
  91. [91]
    US-CERT SHARPKNOT June 2018

    US-CERT. (2018, March 09). Malware Analysis Report (MAR) - 10135536.11.WHITE. Retrieved June 13, 2018.

    Open source URL
  92. [92]
    Trend Micro KillDisk 1

    Fernando Merces, Byron Gelera, Martin Co. (2018, June 7). KillDisk Variant Hits Latin American Finance Industry. Retrieved January 12, 2021.

    Open source URL
  93. [93]
    Symantec Elfin Mar 2019

    Security Response attack Investigation Team. (2019, March 27). Elfin: Relentless Espionage Group Targets Multiple Organizations in Saudi Arabia and U.S.. Retrieved April 10, 2019.

    Open source URL
  94. [94]
    Cadet Blizzard emerges as novel threat actor

    Microsoft Threat Intelligence. (2023, June 14). Cadet Blizzard emerges as a novel and distinct Russian threat actor. Retrieved July 10, 2023.

    Open source URL
  95. [95]
    Ready.gov IT DRP

    Ready.gov. (n.d.). IT Disaster Recovery Plan. Retrieved March 15, 2019.

    Open source URL
  96. [96]
    Unit42 Agrius 2023

    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

    Open source URL
  97. [97]
    Unit42 Agrius 2023

    Or Chechik, Tom Fakterman, Daniel Frank & Assaf Dahan. (2023, November 6). Agonizing Serpens (Aka Agrius) Targeting the Israeli Higher Education and Tech Sectors. Retrieved May 22, 2024.

    Open source URL
  98. [98]
    SentinelOne Agrius 2021

    Amitai Ben & Shushan Ehrlich. (2021, May). From Wiper to Ransomware: The Evolution of Agrius. Retrieved May 21, 2024.

    Open source URL
  99. [99]
    CISA Iran Albanian Attacks September 2022

    CISA. (2022, September 23). AA22-264A Iranian State Actors Conduct Cyber Operations Against the Government of Albania. Retrieved August 6, 2024.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.