T1561.002: T1561.002
Essential information
- MITRE technique ID
T1561.002- Confidence
- 100/100
- Revoked
- No
- Published
- 16/12/2025 19:37
- Modified
- 15/04/2026 12:25
- Author / Source
- The MITRE Corporation
Aliases
Disk Structure Wipe
Platforms
windows macos linux Network Devices
Description
Kill chain phases
| Kill chain | Phase |
|---|---|
| mitre-attack | impact |
Marking (TLP)
TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Intrusion sets, malware, reports, vulnerabilities, indicators and other entities linked to this technique.
Intrusion sets (APT) (10)
-
BlackJack usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 06:41 · Modified 21/12/2025 06:41
-
The MITRE Corporation Confidence 100
[Saint Bear](https://attack.mitre.org/groups/G1031) is a Russian-nexus threat actor active since early 2021, primarily targeting entities in Ukraine and Georgia. The group is notable for a specific remote access tool, …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13 -
The MITRE Corporation Confidence 100
[APT38](https://attack.mitre.org/groups/G0082) is a North Korean state-sponsored threat group that specializes in financial cyber operations; it has been attributed to the Reconnaissance General Bureau.(Citation: CISA AA20-239A BeagleBoyz August 2020) …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 04/05/2026 16:33 -
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 16/03/2026 11:51 · Modified 16/03/2026 11:51
-
Key Group usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 06:45 · Modified 21/12/2025 06:45
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 04/03/2026 16:46 · Modified 04/03/2026 16:46
-
The MITRE Corporation Confidence 100
[Lazarus Group](https://attack.mitre.org/groups/G0032) is a North Korean state-sponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). (Citation: US-CERT HIDDEN COBRA June 2017) (Citation: Treasury North Korean Cyber …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13 -
The MITRE Corporation Confidence 100
[APT37](https://attack.mitre.org/groups/G0067) is a North Korean state-sponsored cyber espionage group that has been active since at least 2012. The group has targeted victims primarily in South Korea, but also …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:14 -
The MITRE Corporation Confidence 100
[Sandworm Team](https://attack.mitre.org/groups/G0034) is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455.(Citation: …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:13 -
AlienVault Confidence 100
[VOID MANTICORE](https://attack.mitre.org/groups/G1055) is a threat group assessed to operate on behalf of Iran’s Ministry of Intelligence and Security (MOIS).(Citation: Check Point VOID MANTICORE Handala Hack March 2026) Active …
First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 04:51 · Modified 04/05/2026 16:33
Malware (44)
-
WhisperGate - S0689 usesFamilyPublished 10/06/2025 18:09 · Modified 10/06/2025 18:09
- Meteor - S0688
-
ShrinkLocker usesFamilyPublished 17/09/2024 11:15 · Modified 17/09/2024 11:15
-
Filerase usesFamilyPublished 04/03/2026 15:30 · Modified 04/03/2026 15:30
-
Shamoon - S0140 usesFamilyPublished 04/03/2026 15:30 · Modified 04/03/2026 15:30
-
WhisperGate usesFamilyPublished 09/09/2024 08:02 · Modified 09/09/2024 08:02
-
LockBit usesFamilyPublished 06/05/2026 10:26 · Modified 06/05/2026 10:26
-
Hakuna Matata usesFamilyPublished 02/10/2024 08:51 · Modified 02/10/2024 08:51
- CaddyWiper
-
CaddyWiper - S0693 usesFamilyPublished 30/01/2026 18:42 · Modified 30/01/2026 18:42
-
Handala Wiper usesFamilyPublished 16/03/2026 10:24 · Modified 16/03/2026 10:24
- StoneDrill
- DEADWOOD
-
HermeticWiper usesFamilyPublished 30/01/2026 18:42 · Modified 30/01/2026 18:42
- Destover
-
ZeroCleare usesFamily The MITRE Corporation Confidence 100
[ZeroCleare](https://attack.mitre.org/software/S1151) is a wiper malware that has been used in conjunction with the [RawDisk](https://attack.mitre.org/software/S0364) driver since at least 2019 by suspected Iran-nexus threat actors including activity targeting the …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:37 · Modified 27/03/2026 01:05 -
SHAPESHIFT usesFamilyPublished 04/03/2026 15:30 · Modified 04/03/2026 15:30
- StoneDrill - S0380
- Shamoon
-
Slam usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 21:56 · Modified 20/12/2025 21:56
-
IOCONTROL usesFamilyPublished 04/03/2026 15:30 · Modified 04/03/2026 15:30
-
Xorist usesFamilyPublished 02/10/2024 08:51 · Modified 02/10/2024 08:51
-
RuRansom usesFamilyPublished 02/10/2024 08:51 · Modified 02/10/2024 08:51
-
Lotus Wiper usesFamilyPublished 21/04/2026 12:09 · Modified 21/04/2026 12:09
- IsraBye
- Ordinypt
- Apostle
-
UX-Cryptor usesFamilyPublished 02/10/2024 08:51 · Modified 02/10/2024 08:51
-
Judge/NoCry usesFamilyPublished 02/10/2024 08:51 · Modified 02/10/2024 08:51
- IsaacWiper
-
RustyWater usesFamilyPublished 04/03/2026 15:30 · Modified 04/03/2026 15:30
-
GhostFetch usesFamilyPublished 04/03/2026 15:30 · Modified 04/03/2026 15:30
- Petya
- MultiLayer Wiper
- SQLShred
-
Chaos - S0220 usesFamilyPublished 09/10/2025 03:41 · Modified 09/10/2025 03:41
- KillDisk - S0607
-
Annabelle usesFamilyPublished 02/10/2024 08:51 · Modified 02/10/2024 08:51
-
Tickler usesFamilyPublished 04/03/2026 15:30 · Modified 04/03/2026 15:30
-
njRAT - S0385 usesFamilyPublished 16/09/2025 13:41 · Modified 16/09/2025 13:41
-
ZeroCleare - S1151 usesFamilyPublished 04/03/2026 15:30 · Modified 04/03/2026 15:30
-
NJRat usesFamilyPublished 05/03/2025 11:12 · Modified 05/03/2025 11:12
- BFG Agonizer
- KillDisk
Reports (4)
-
19 MITREs 1 MalwarePublished 21/04/2026 12:09 · Modified 21/04/2026 15:28
-
1 CVE 20 MITREs 10 Malwares 1 Observable 1 APTPublished 04/03/2026 15:30 · Modified 04/03/2026 15:46
-
18 MITREs 12 Malwares 1 APTPublished 01/10/2024 19:48 · Modified 01/10/2024 20:53
-
20 MITREs 3 Malwares 1 Observable 1 APTPublished 25/09/2024 19:49 · Modified 25/09/2024 20:11
Vulnerabilities (CVE) (1)
Check Point Quantum Security Gateways contain an unspecified information disclosure vulnerability. The vulnerability potentially allows an attacker to access information on Gateways …
- Attack vector
- Network
- Published
- 30/05/2024
- Modified
- 04/03/2026
Attack patterns (MITRE) (1)
-
T1561 subtechnique-ofDisk Wipe
Tool (2)
-
RawDisk usesThe MITRE Corporation Confidence 100
[RawDisk](https://attack.mitre.org/software/S0364) is a legitimate commercial driver from the EldoS Corporation that is used for interacting with files, disks, and partitions. The driver allows for direct modification of data …
Published 25/03/2019 13:30 · Modified 27/03/2026 01:07 -
Diskpart usesThe MITRE Corporation Confidence 75
[Diskpart](https://attack.mitre.org/software/S9002) is a Windows command-line utility that is used to manage the computer’s drives, which includes disks, partitions, volumes and virtual hard disks.(Citation: Microsoft_diskpart_Feb2023) Adversaries may abuse [Diskpart](https://attack.mitre.org/software/S9002) …
Published 26/01/2026 19:36 · Modified 04/05/2026 16:31
Campaign (1)
- HomeLand Justice uses
Course Of Action (1)
- Data Backup mitigates