KillDisk is a destructive malware family primarily used to wipe data and render compromised systems inoperable. Variants overwrite files, critical operating-system data, and disk structures, including the master boot record, preventing normal startup and hindering recovery. Windows implementations can access physical disks through native APIs and force the machine to shut down after destructive operations. The family also includes ransomware variants affecting Windows and Linux; some encrypt files using AES and protect the encryption keys with RSA.
KillDisk is associated with BlackEnergy and the Russian GRU-linked Sandworm Team. During the December 2015 attacks against Ukrainian electricity distribution companies, attackers deployed it through BlackEnergy to destroy Windows systems, including human-machine interfaces, and impede restoration of the SCADA environment. KillDisk was a destructive component of the operation, distinct from the attackers' actions to open electricity breakers. It has also been used against Ukrainian banks and financial institutions in Latin America. North Korean-linked operators, including APT38 and Lazarus-associated actors, have used KillDisk in financially motivated operations, including disk wiping for anti-forensics and a destructive attack against a Central American online casino. Its use by multiple threat groups means that its presence alone does not establish attribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Kill Disk ... CVE-2014-0751 ... Christmas 2015 Attacks
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Sandworm Team has used the BlackEnergy KillDisk component to corrupt the infected system's master boot record.
"The most recent case was APT38 ... which was a financially-motivated threat cluster, which leveraged disk-wipe techniques (KillDisk) as an anti-forensics measure in 2017."
they deployed various malicious tools, including disk-wiping malware from the KillDisk family.
DOJ’s 2020 GRU Unit 74455 indictment describes destructive malware operations against Ukraine’s power grid, Ministry of Finance, and State Treasury Service, including BlackEnergy, Industroyer, and KillDisk, as part of a wider destabilization campaign.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
Numerous entries mention enumerating drives, logical disks, disk type, free space, or volume information; examples include 'Babuk can enumerate disk volumes,' 'Cuba can enumerate local drives,' and 'TAINTEDSCRIBE can use DriveList to retrieve drive information.'
Sandworm Team has used the BlackEnergy KillDisk component to overwrite files on Windows-based Human-Machine Interfaces.
the specific list of extensions used by ExPetr is very similar to the one used by BlackEnergy’s KillDisk ransomware from 2015 and 2016
destruction of serial-to-Ethernet devices through malicious firmware updates
The December, 2015 attack on the Ukrainian power grid left nearly 230,000 people without power
we saw a variant of the disk-wiping KillDisk malware hitting several financial institutions in Latin America... we uncovered a master boot record (MBR)-wiping malware in the same region.
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
68 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware / Outils # FakePenny (ransomware) Maui (ransomware) H0lyGh0st (ransomware) KillDisk (other) Qilin (ransomware) Play (ransomware)
Disk-wiping malware/technique reportedly leveraged by APT38 as an anti-forensics measure.
Destructive malware associated with GRU Unit 74455 and used in operations that rendered systems unable to perform their assigned functions.
Destructive wiper malware used in Russian operations against Ukrainian government and power-sector entities.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.