T1561.001: T1561.001
Essential information
- MITRE technique ID
T1561.001- Confidence
- 100/100
- Revoked
- No
- Published
- 16/12/2025 19:38
- Modified
- 21/04/2026 17:28
- Author / Source
- The MITRE Corporation
Aliases
Disk Content Wipe
Platforms
windows macos linux Network Devices
Description
Kill chain phases
| Kill chain | Phase |
|---|---|
| mitre-attack | impact |
Marking (TLP)
TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Intrusion sets, malware, reports, vulnerabilities, indicators and other entities linked to this technique.
Intrusion sets (APT) (6)
-
Vect usesRansomware.Live Confidence 100
No description available
First seen 01/01/1970 · Last seen 16/11/5138 Published 06/01/2026 21:23 · Modified 04/05/2026 16:30 -
The MITRE Corporation Confidence 100
[Gamaredon Group](https://attack.mitre.org/groups/G0047) is a suspected Russian cyber espionage group that has targeted military, law enforcement, judiciary, non-profit, and non-governmental organizations in Ukraine since at least 2013. The name …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 04/05/2026 16:33 -
Sandworm usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 23:15 · Modified 20/12/2025 23:15
-
The MITRE Corporation Confidence 100
[Lazarus Group](https://attack.mitre.org/groups/G0032) is a North Korean state-sponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). (Citation: US-CERT HIDDEN COBRA June 2017) (Citation: Treasury North Korean Cyber …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13 -
AlienVault Confidence 100
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) is a threat group assessed to operate on behalf of Iran’s Ministry of Intelligence and Security (MOIS).(Citation: Check Point VOID MANTICORE Handala Hack March 2026) Active …
First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 04:51 · Modified 04/05/2026 16:33 -
Yurei usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 16:06 · Modified 21/12/2025 16:06
Malware (48)
-
AcidRain usesFamilyPublished 13/11/2025 23:20 · Modified 13/11/2025 23:20
-
FamilyPublished 30/01/2026 18:42 · Modified 30/01/2026 18:42
-
ZeroCleare usesFamily The MITRE Corporation Confidence 100
[ZeroCleare](https://attack.mitre.org/software/S1151) is a wiper malware that has been used in conjunction with the [RawDisk](https://attack.mitre.org/software/S0364) driver since at least 2019 by suspected Iran-nexus threat actors including activity targeting the …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:37 · Modified 27/03/2026 01:05 - IsaacWiper
- Destover
-
DarkGate usesFamilyPublished 21/08/2025 21:03 · Modified 21/08/2025 21:03
-
CaddyWiper - S0693 usesFamilyPublished 30/01/2026 18:42 · Modified 30/01/2026 18:42
- SQLShred
-
DoubleZero usesFamilyPublished 30/01/2026 18:42 · Modified 30/01/2026 18:42
- Ordinypt
-
Sting wiper usesFamilyPublished 30/01/2026 18:42 · Modified 30/01/2026 18:42
- Apostle
- Meteor - S0688
-
SwiftSlicer usesFamilyPublished 30/01/2026 18:42 · Modified 30/01/2026 18:42
- KillDisk - S0607
- AcidPour
-
BidSwipe usesFamilyPublished 30/01/2026 18:42 · Modified 30/01/2026 18:42
-
SOLOSHRED usesFamilyPublished 30/01/2026 18:42 · Modified 30/01/2026 18:42
-
SharpNikoWiper usesFamilyPublished 30/01/2026 18:42 · Modified 30/01/2026 18:42
-
ZEROLOT usesFamilyPublished 30/01/2026 18:42 · Modified 30/01/2026 18:42
-
ARGUEPATCH usesFamilyPublished 30/01/2026 18:42 · Modified 30/01/2026 18:42
-
Vect usesFamilyPublished 30/04/2026 23:40 · Modified 30/04/2026 23:40
-
SatanLockv2 usesFamilyPublished 12/09/2025 15:33 · Modified 12/09/2025 15:33
-
Shamoon - S0140 usesFamilyPublished 04/03/2026 15:30 · Modified 04/03/2026 15:30
-
Prince-Ransomware usesFamilyPublished 12/09/2025 15:33 · Modified 12/09/2025 15:33
-
Lotus Wiper usesFamilyPublished 21/04/2026 12:09 · Modified 21/04/2026 12:09
- Petya
-
HermeticWiper usesFamilyPublished 30/01/2026 18:42 · Modified 30/01/2026 18:42
-
VPNFilter usesFamilyPublished 13/11/2025 23:20 · Modified 13/11/2025 23:20
- IsraBye
-
HermeticRansom usesFamilyPublished 30/01/2026 18:42 · Modified 30/01/2026 18:42
-
Prestige - S1058 usesFamilyPublished 30/01/2026 18:42 · Modified 30/01/2026 18:42
-
Industroyer2 - S1072 usesFamilyPublished 30/01/2026 18:42 · Modified 30/01/2026 18:42
-
ORCSHRED usesFamilyPublished 30/01/2026 18:42 · Modified 30/01/2026 18:42
-
NikoWiper usesFamilyPublished 30/01/2026 18:42 · Modified 30/01/2026 18:42
- MegaCortex
-
ZOV wiper usesFamilyPublished 30/01/2026 18:42 · Modified 30/01/2026 18:42
-
RansomBoggs usesFamilyPublished 30/01/2026 18:42 · Modified 30/01/2026 18:42
-
WhisperGate - S0689 usesFamilyPublished 10/06/2025 18:09 · Modified 10/06/2025 18:09
- StoneDrill
-
Yurei usesFamilyPublished 14/11/2025 12:16 · Modified 14/11/2025 12:16
- DEADWOOD
-
ROARBAT usesFamilyPublished 30/01/2026 18:42 · Modified 30/01/2026 18:42
-
DynoWiper usesFamilyPublished 21/05/2026 23:03 · Modified 21/05/2026 23:03
-
AWFULSHRED usesFamilyPublished 30/01/2026 18:42 · Modified 30/01/2026 18:42
- BlackCat
- StoneDrill - S0380
-
WhisperGate usesFamilyPublished 09/09/2024 08:02 · Modified 09/09/2024 08:02
Reports (2)
-
AlienVault Confidence 100 21 MITREs 1 Malware 8 IOCs 8 Observables 1 APTPublished 28/04/2026 18:34 · Modified 29/04/2026 07:14 · threat-report
-
19 MITREs 1 MalwarePublished 21/04/2026 12:09 · Modified 21/04/2026 15:28
Attack patterns (MITRE) (1)
-
T1561 subtechnique-ofDisk Wipe
Tool (2)
-
RawDisk usesThe MITRE Corporation Confidence 100
[RawDisk](https://attack.mitre.org/software/S0364) is a legitimate commercial driver from the EldoS Corporation that is used for interacting with files, disks, and partitions. The driver allows for direct modification of data …
Published 25/03/2019 13:30 · Modified 27/03/2026 01:07 -
cipher.exe usesThe MITRE Corporation Confidence 100
[cipher.exe](https://attack.mitre.org/software/S1205) is a native Microsoft utility that manages encryption of directories and files on NTFS (New Technology File System) partitions by using the Encrypting File System (EFS).(Citation: cipher.exe)
Published 25/02/2025 18:31 · Modified 27/03/2026 01:07
Campaign (1)
- APT28 Nearest Neighbor Campaign uses
Course Of Action (1)
- Data Backup mitigates