KillDisk Variant Hits Latin American Financial Groups

2018-01-15 Trend Micro

https://www.trendmicro.com/en_us/research/18/a/new-killdisk-variant-hits-financial-organizations-in-latin-america.html

Thumbnail for KillDisk Variant Hits Latin American Financial Groups

Trend Micro found a new KillDisk variant targeting financial organizations in Latin America, but the excerpt does not attribute the activity to a named threat actor. The malware appears to be intentionally dropped by another process or used as part of a larger attack package, with hardcoded paths and a rename routine that leaves a zero-byte artifact during execution. It wipes files across fixed and removable drives, overwrites MBR, EBR, and volume sectors, and then attempts to force a reboot by terminating critical Windows processes or calling the system reboot function. Unlike earlier ransomware-themed KillDisk activity, this variant has no ransom note, making its primary impact destructive data loss rather than extortion.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 8a81a1d0fae933862b51f63064069aa… 2018-01-15 2020-03-09

Related Reports

« Back