SDelete is a legitimate Microsoft Sysinternals command-line utility for secure file deletion on Windows. It overwrites data before removal so that deleted content is difficult or impractical to recover, making it useful for anti-forensics, evidence destruction, and operational cleanup. In intrusion activity, it has been used to remove malware artifacts, tools, temporary files, staged data, and other traces from compromised systems. It is associated with ATT&CK-style behaviors centered on deleting evidence and hindering forensic recovery rather than functioning as a standalone malicious family.
Multiple threat actors have used SDelete during post-compromise cleanup, including APT29 and FIN5, and Sandworm-linked operations have incorporated it in destructive campaigns in Ukraine. It has also been used as a building block for destructive tooling; NikoWiper is based on the SDelete utility. In reported incidents, SDelete has appeared alongside wipers and other destructive components to erase artifacts or contribute to broader integrity and availability impacts.
Because SDelete is an administrative utility with legitimate enterprise uses, its presence alone is not sufficient to indicate malicious activity. Detection and triage typically depend on surrounding context such as suspicious execution chains, batch or scheduled-task deployment, concurrent destructive tooling, or use immediately after intrusion activity. High-confidence characterization supports Windows as the relevant platform and defense-evasion through secure deletion as its primary adversarial use case.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"...а також легітимної утиліти SDelete (запуск якої передбачалося здійснити за допомогою "news.bat")"
9 distinct techniques documented for this family, organized by ATT&CK tactic.
MSTIC researchers also spotted abuse of Sdelete in data destruction operations. While Sdelete was designed as a utility to securely erase files on Windows systems, it’s just as useful to threat actors like ‘IRIDIUM’ who’ll rename it ‘cdel.exe’ and effectively use it as a wiper.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Legitimate Sysinternals secure-deletion utility referenced as being abused by ransomware actors to destroy forensic artifacts (data destruction/anti-forensics).
Secure deletion utility used offensively here to irrecoverably delete data.
Sdelete is a secure deletion utility that can be used to irreversibly delete files and data. In this context it is associated with ATT&CK technique T1485, indicating destructive or data-wiping behavior.
Legitimate Microsoft secure-deletion utility abused/used in destructive activity (basis for NikoWiper; also observed executed directly in Jan 2023).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.