KillDisk is a destructive Windows malware family used to render systems inoperable by deleting files and corrupting low-level disk structures, including the master boot record, leaving hosts unbootable and complicating recovery. It is closely associated with Russian GRU Unit 74455, widely tracked as Sandworm or Seashell Blizzard, and has been repeatedly linked to disruptive operations against Ukrainian government and critical infrastructure targets. In the December 2015 attack on Ukraine’s electric power sector, KillDisk was deployed alongside BlackEnergy intrusions and manual operator actions against SCADA environments to wipe Windows systems and hinder restoration after breakers were opened. It was also used in subsequent destructive activity against Ukrainian government and financial targets, and later reporting tied updated variants to attacks on high-value financial organizations in Ukraine in 2016.
KillDisk has been described both as a standalone wiper and as a destructive component or plugin delivered through BlackEnergy. Reported behavior includes erasing selected files, overwriting or corrupting the master boot record, and damaging systems so they cannot boot normally. Its operational role has typically been post-compromise disruption and recovery denial rather than initial intrusion. Documented campaigns place it in broader Sandworm tradecraft that combined credential theft, remote access into enterprise and OT-adjacent environments, hands-on-keyboard operations, and denial-of-service activity to maximize operational impact. The malware is historically significant as part of some of the earliest publicly documented cyber operations to produce power outages and sustained disruption in critical infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The US Department of Justice attributed KillDisk, Industroyer, NotPetya, and Olympic Destroyer operations to GRU officers associated with the unit.
DOJ’s 2020 GRU Unit 74455 indictment describes destructive malware operations against Ukraine’s power grid, Ministry of Finance, and State Treasury Service, including BlackEnergy, Industroyer, and KillDisk, as part of a wider destabilization campaign.
The final payload is a RAT module, with TCP communications and its commands indexed by 32-bit integers, cf. KillDisk in Central America.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
Astaroth uses the LoadLibraryExW() function to load additional modules. Attor's dispatcher can execute additional plugins by loading the respective DLLs. ... LightSpy's main executable and module .dylib binaries are loaded using ... dlopen() ... dlsym() ... RotaJakiro uses ... .so files ... using dlopen() and dlsym().
...uses the LoadLibraryExW() function to load additional modules... execute additional plugins by loading the respective DLLs... loaded and executed DLLs in memory during runtime... loads a dynamic library (.dylib file) using dlopen() and obtains a function pointer... using dlopen() and dlsym()... calls LoadLibrary then executes exports from a DLL.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
APT41 used VMProtected binaries in multiple intrusions. BackdoorDiplomacy has obfuscated tools and malware it uses with VMProtect. KillDisk uses VMProtect to make reverse engineering the malware more difficult. Turian can use VMProtect for obfuscation.
"created using Nullsoft Scriptable Install System (NSIS)... purposely named it 'MBR Killer.'"
“APT28 has cleared event logs, including by using the commands wevtutil cl System and wevtutil cl Security …” / “APT38 clears Window Event logs and Sysmon logs …” / “BlackCat can clear Windows event logs using wevtutil.exe …” / “NotPetya uses wevtutil to clear the Windows event logs …”
Examples include "Cryptoistic can scan a directory to identify files for deletion" and "KillDisk has used the FindNextFile command as part of its file deletion process."
...uses the LoadLibraryExW() function to load additional modules... execute additional plugins by loading the respective DLLs... loaded and executed DLLs in memory during runtime... loads a dynamic library (.dylib file) using dlopen() and obtains a function pointer... using dlopen() and dlsym()... calls LoadLibrary then executes exports from a DLL.
The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
Multiple entries describe enumerating local, logical, or physical drives and disk/volume information, e.g., 'can enumerate local drives,' 'GetLogicalDrives,' 'fsutil fsinfo drives,' 'list drives,' and 'discover logical drive information including the drive type, free space, and volume information.'
BlackEnergy is a modular backdoor that can be used for several purposes, like espionage and downloading of destructive components... BlackEnergy used its modular architecture that supports several plugins to download and keep running both a variant of Dropbear SSH backdoor and a new destructive plugin called KillDisk.
After gaining internal access, the attacker conducted reconnaissance and prepared destructive actions including firmware damage, system-file deletion, and custom wiper execution.
Ukrainian Government & Critical Infrastructure: December 2015 through December 2016 destructive malware attacks against Ukraine’s electric power grid, Ministry of Finance, and State Treasury Service, using malware known as BlackEnergy, Industroyer, and KillDisk
The attackers didn’t just open breakers. They deployed KillDisk malware to prevent system restoration.
During this incident attackers manually opened circuit breakers after HMI takover, wiped SCADA servers using KillDisk, and overwhelmed call centers with DoS attacks.
"AcidPour includes functionality to reboot the victim system following wiping actions..."; "AcidRain reboots the target system once the various wiping processes are complete"; "Apostle reboots the victim machine following wiping"; "APT37 ... issue the command shutdown /r /t 1 to reboot a system after wiping its MBR"; "APT38 ... BOOTWRECK ... initiate a system reboot after wiping the victim's MBR"; "Black Basta ... used ShellExecuteA to shut down and restart"; "DarkGate ... used the shutdown command"; "HermeticWiper can initiate a system shutdown"; "NotPetya will reboot the system one hour after infection"; "Shamoon will reboot the infected system once the wiping functionality has been completed"; "WhisperGate can shutdown ... through ... ExitWindowsEx"
The KillDisk malware erases selected files on target systems and corrupts the master boot record, rendering systems inoperable.
Destructive TTPs such as wiping or even bricking are not novel... CIH virus... overwriting a hard drive's partition table... BrickerBot destroyed more than 10 million IoT devices by writing random data to various block devices... AcidRain's wiper functionality consists of recursive file deletion combined with either overwriting raw block devices or erasing them through dedicated IOCTLs.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
47 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Destructive malware associated with GRU Unit 74455 and used in operations that rendered systems unable to perform their assigned functions.
Destructive wiper malware used in Russian operations against Ukrainian government and power-sector entities.
Destructive wiper used alongside the Ukraine 2015 BlackEnergy intrusion.
Destructive wiper family previously used in Sandworm-linked campaigns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.