Wiper
The MITRE Corporation
· Published 31/05/2017 23:32 · Modified 27/03/2026 01:05
Family
Essential information
- Confidence
- 100/100
- Is family
- Yes
- Published
- 31/05/2017 23:32
- Modified
- 27/03/2026 01:05
- Revoked
- No
- Author / Source
- The MITRE Corporation
- Related entities
- 20 attack patterns (mitre), 1 intrusion sets (apt), 3 sectors, 22 indicators
Description
[Wiper](https://attack.mitre.org/software/S0041) is a family of destructive malware used in March 2013 during breaches of South Korean banks and media companies. (Citation: Dell Wiper)
Marking (TLP)
TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Attack patterns, malware, vulnerabilities, indicators, intrusion sets and other entities linked to this malware.
Attack patterns (MITRE) (20)
-
T1574 usesHijack Execution Flow MITRE
-
T1505 usesServer Software Component MITRE
-
T1106 usesNative API MITRE
-
T1059 usesCommand and Scripting Interpreter MITRE
-
T1046 usesNetwork Service Discovery MITRE
-
T1070 usesIndicator Removal MITRE
-
T1553 usesSubvert Trust Controls MITRE
-
T1176 usesSoftware Extensions MITRE
-
T1543 usesCreate or Modify System Process MITRE
-
T1547 usesBoot or Logon Autostart Execution MITRE
-
T1053 usesScheduled Task/Job MITRE
-
T1003 usesOS Credential Dumping MITRE
Intrusion sets (APT) (1)
-
The MITRE Corporation Confidence 100
[Agrius](https://attack.mitre.org/groups/G1030) is an Iranian threat actor active since 2020 notable for a series of ransomware and wiper operations in the Middle East, with an emphasis on Israeli targets.(Citation:…
First seen 01/01/1970 · Last seen 16/11/5138 ·
Sectors (3)
-
Technology targets
-
Education targets
-
Universities targets
Indicators (22)
-
stix 100/100 Revoked· Valid until 08/02/2025 · Source: AlienVault
-
stix 100/100 Revoked
TEL:Hacktool:Win32/Kingron.A
· Valid until 08/02/2025 · Source: AlienVault -
stix 100/100 Revoked· Valid until 08/02/2025 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 08/02/2025 · Source: AlienVault
-
stix 100/100 Revoked
research_pe_signed_outside_timestamp
· Valid until 08/02/2025 · Source: AlienVault -
stix 100/100 Revoked· Valid until 08/02/2025 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 08/02/2025 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 08/02/2025 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 08/02/2025 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 08/02/2025 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 08/02/2025 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 23/03/2026 · Source: AlienVault