KillDisk is a destructive malware family best known for disk- and system-wiping operations associated with Russian state activity, especially Sandworm/TeleBots operations against Ukraine. It has been used as a destructive component alongside BlackEnergy in attacks on electric utilities and other organizations, where its purpose was to render Windows systems inoperable, impede recovery, and amplify operational disruption during broader intrusion activity. Public reporting also describes later KillDisk variants used against financial institutions in Latin America and references to Linux and macOS-targeting ransomware-capable variants, indicating the family evolved beyond a single Windows-only implementation.
On Windows, KillDisk has been observed obtaining direct access to physical drives and overwriting critical disk structures, including the master boot record or early disk sectors, then forcing system shutdown or reboot so the damage becomes immediately apparent. In Ukrainian power-sector incidents, KillDisk was deployed after credential theft, remote access, and hands-on-keyboard operations in SCADA environments, where it was used to wipe SCADA and enterprise systems and hinder restoration efforts. Some variants also targeted files by extension and displayed ransom-style messaging, but the family is primarily characterized in high-confidence reporting as a wiper rather than profit-motivated ransomware.
KillDisk is strongly linked to Sandworm, a GRU-associated threat actor, and has been cited in U.S. government attributions and indictments concerning destructive operations against Ukraine’s power grid, government entities, and banks. It has also appeared in reporting on TeleBots activity and in a Lazarus-linked intrusion against a Central American online casino, though the most established association remains with Sandworm’s disruptive campaigns. Victims have included energy-sector organizations, financial institutions, and other enterprises where destructive impact or distraction supported broader operational objectives.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Kill Disk ... CVE-2014-0751 ... Christmas 2015 Attacks
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The actors deployed BlackEnergy malware to steal user credentials and used its destructive malware component, KillDisk, to make infected computers inoperable.
they deployed various malicious tools, including disk-wiping malware from the KillDisk family.
DOJ’s 2020 GRU Unit 74455 indictment describes destructive malware operations against Ukraine’s power grid, Ministry of Finance, and State Treasury Service, including BlackEnergy, Industroyer, and KillDisk, as part of a wider destabilization campaign.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
Sometimes malware distributors decide to use a packer in order to increase the chance of avoiding detection by a security solution and to harden the binary against analysis... They tend to use commercial packers like VMProtect, Enigma Protector or Themida, but we recorded few instances where they also used a crypter – a custom malware packer.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
Numerous entries mention enumerating drives, logical disks, disk type, free space, or volume information; examples include 'Babuk can enumerate disk volumes,' 'Cuba can enumerate local drives,' and 'TAINTEDSCRIBE can use DriveList to retrieve drive information.'
Their attacks spanned the globe, including the worldwide 2017 NotPetya outbreak that did more than $1 billion in damage ... Besides NotPetya, the alleged co-conspirators were behind destructive malware attacks beginning in December 2015 that disrupted Ukraine’s electricity grid
the specific list of extensions used by ExPetr is very similar to the one used by BlackEnergy’s KillDisk ransomware from 2015 and 2016
The December, 2015 attack on the Ukrainian power grid left nearly 230,000 people without power
the attackers then proceeded to brick those remote controls... deployed a “wiper” to brick the computers used to control the grid
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
62 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Destructive malware associated with GRU Unit 74455 and used in operations that rendered systems unable to perform their assigned functions.
Destructive wiper malware used in Russian operations against Ukrainian government and power-sector entities.
Destructive wiper used alongside the Ukraine 2015 BlackEnergy intrusion.
Destructive wiper family previously used in Sandworm-linked campaigns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.