AWFULSHRED is a destructive Linux wiper implemented as an obfuscated shell script and used by Sandworm, the Russian military intelligence threat group associated with GRU Unit 74455. It is designed to corrupt or erase data and render compromised systems unusable. The script uses the shred utility to overwrite data, stops services, kills processes, deactivates swap, and can disable or corrupt Apache, HTTP, and SSH services. It also clears Bash history and can enable Linux SysRq functions to force a system reboot, combining destructive activity with measures that impede investigation and recovery.
Sandworm deployed AWFULSHRED during the April 2022 operation against a Ukrainian energy provider that also involved Industroyer2, CaddyWiper, ORCSHRED, and SOLOSHRED. The coordinated operation targeted electrical substations and supporting computing infrastructure, with disk-wiping tools intended to hinder recovery. AWFULSHRED was subsequently identified in the January 2023 destructive attack against Ukrinform, Ukraine’s national news agency, alongside other wiping tools. Its documented targets therefore include Linux systems in Ukrainian energy and media organizations. The initial access method for the April 2022 operation remains unknown.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Industroyer2 has also been accompanied by various wiper malware types, including “CaddyWiper,” “ORCSHRED,” “SOLOSHRED,” and “AWFULSHRED.”
6 distinct techniques documented for this family, organized by ATT&CK tactic.
Among the tools that Sandworm deployed on the energy company's network was a Windows disk wiper called CaddyWiper and similar disk-wiping tools dubbed Orcshred, Soloshred, and Awfulshred for Linux and Solaris systems.
This obfuscated malicious script can also disable and corrupts apache, HTTP and SSH services
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
AwfulShred is referenced in the associated analytic story list in the context of compromised Linux hosts and data destruction.
Linux malware associated with enabling all SysRq functions to manipulate kernel system requests, potentially allowing reboot or other critical system actions that can lead to instability or compromise.
Linux malware associated here with data destruction activity; the content only references it as an analytic story and does not provide technical behavior details.
AwfulShred is referenced in the analytic story context related to Linux service restarts and data destruction, indicating relevance to destructive Linux malware activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.