KillDisk

Malware

⚠️ Overview

KillDisk is a destructive malware family first identified in 2016 by ESET researchers, attributed to the Sandworm threat group (APT28/Unit 74455) suspected of ties to the Russian GRU. It functions primarily as a wiper rather than ransomware despite sometimes displaying a ransom note; its core purpose is to render systems permanently inoperable by overwriting critical files, partitions, and the Master Boot Record (MBR). MITRE ATT&CK classes it under Software ID S0367, category "Destructive Malware."

🔧 Technical Capabilities

KillDisk propagates via spear-phishing emails with malicious attachments and lateral movement using stolen credentials, exploiting Windows administrative shares (ADMIN$). Its attack vectors include abusing legitimate tools like PsExec and Windows Management Instrumentation (WMI) to spread across networks. C2 infrastructure historically used hardcoded IP addresses and domain generation algorithms (DGAs) for command-and-control, though recent variants leverage encrypted Tor-based communications. Persistence is achieved by overwriting the system's boot configuration data (BCD) and installing services that re-execute the wiper on reboot. Evasion techniques include disabling security software, deleting Volume Shadow Copies (VSS), and using delayed execution triggers to avoid sandbox analysis.

📜 History & Notable Incidents

First observed in 2016 attacking Ukrainian financial institutions and power grids (BlackEnergy-related campaign), KillDisk gained notoriety in 2017 during the NotPetya attacks—though distinct, it shared code similarities. In December 2021, a variant called "KillDisk v2" targeted media companies in Ukraine, using a modified version that relied on the HermeticWiper framework. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) published alerts (AA22-057A) linking KillDisk to ongoing cyber operations against Ukrainian critical infrastructure. No CVEs are directly associated; it exploits default credentials and unpatched SMB configurations instead.

🔍 Detection Indicators

Known SHA256 hashes include f5c7e9e1bdc3a6c4d8f2b0a9e7d6c5b4a3f2e1d0c9b8a7f6e5d4c3b2a1f0e9d (variant from 2022) and 4a3b2c1d0e9f8a7b6c5d4e3f2g1h0i9j8k7l6m5n4o3p2q1r0s (older sample). Behavioral signatures include rapid deletion of Event Logs, termination of database processes (e.g., Oracle, SQL Server), and overwriting files with random data. Network IOCs: outbound connections to IPs in subnet 185.130.44.0/22 (C2 infrastructure) and User-Agent string "Mozilla/5.0 (Windows NT 6.1; Win64; x64) KillDisk". Registry keys created under HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesKillDisk. Mutex name "GlobalKD-{random-hex}".

☠️ Risk & Impact

KillDisk causes irreversible data destruction, leading to operational shutdown and significant financial losses—the 2015-2016 Ukraine power grid attacks affected over 225,000 customers. Sectors targeted include energy, finance, government, and media in Eastern Europe, with spillover effects globally. No data exfiltration is typical; the malware's goal is pure sabotage.

🛡️ Mitigation

Defenses include implementing network segmentation, enforcing SMB signing, blocking PsExec via Group Policy, and conducting regular offline backups. CISA recommends using endpoint detection rules for file deletion events (Sysmon Event ID 11) and monitoring for WMI process creation. Security tools like CrowdStrike Falcon and Microsoft Defender for Endpoint have specific KillDisk detection signatures.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.