AwfulShred is a destructive Linux wiper implemented as a malicious shell script. It is designed to corrupt or erase data on targeted systems by invoking file-overwrite functionality and carrying out additional disruptive actions intended to damage system availability and hinder recovery. Reported behaviors include overwriting files, stopping or corrupting Apache, HTTP, and SSH services, deactivating swap, killing processes, clearing shell history, enabling SysRq functionality, and rebooting the host. The malware has also been described in operations affecting Linux and Unix-class systems, with related reporting noting Linux targeting and some references to Solaris-adjacent destructive activity in the same campaign set, although AwfulShred itself is consistently identified as the Linux component.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In addition to Industroyer2, Sandworm used several destructive malware families including CaddyWiper, ORCSHRED, SOLOSHRED and AWFULSHRED.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
Among the tools that Sandworm deployed on the energy company's network was a Windows disk wiper called CaddyWiper and similar disk-wiping tools dubbed Orcshred, Soloshred, and Awfulshred for Linux and Solaris systems.
This obfuscated malicious script can also disable and corrupts apache, HTTP and SSH services
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
AwfulShred is referenced in the associated analytic story list in the context of compromised Linux hosts and data destruction.
Linux malware associated with enabling all SysRq functions to manipulate kernel system requests, potentially allowing reboot or other critical system actions that can lead to instability or compromise.
Linux malware associated here with data destruction activity; the content only references it as an analytic story and does not provide technical behavior details.
AwfulShred is referenced in the analytic story context related to Linux service restarts and data destruction, indicating relevance to destructive Linux malware activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.