WhiskeyDelta is a Lazarus Group malware family with destructive disk-wiping capability. The provided content states that it can overwrite the first 132 MB or 1.5 MB of each drive using random data from heap memory. More broadly, the source material places WhiskeyDelta within Lazarus Group’s malware ecosystem alongside tools such as WhiskeyAlfa, WhiskeyBravo, SHARPKNOT, KiloAlfa, IndiaIndia, Sumarta, Torisma, and DRATzarus. The content also attributes to Lazarus Group the use of malware including WhiskeyAlfa, WhiskeyBravo, WhiskeyDelta, and SHARPKNOT to wipe disk contents, overwrite the MBR, and render systems unbootable, with some operations followed by replacement of the system wallpaper with a threatening image. High-confidence associations in the content therefore indicate WhiskeyDelta is part of Lazarus-linked destructive operations targeting drive contents on compromised Windows enterprise environments. A directly mentioned behavioral indicator is overwriting the first 132 MB or 1.5 MB of each drive with random heap data.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
WhiskeyDelta can overwrite the first 132MB or 1.5MB of each drive with random data from heap memory.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
"Lazarus Group has used malware like WhiskeyAlfa to overwrite the first 64MB of every drive... attempt to wipe every byte of every sector on every drive."
Lazarus Group has used malware like WhiskeyAlfa to overwrite the first 64MB of every drive with a mix of static and random buffers... WhiskeyBravo can be used to overwrite the first 4.9MB of physical drives. WhiskeyDelta can overwrite the first 132MB or 1.5MB of each drive with random data from heap memory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Lazarus disk-wiping malware that overwrites portions of drives with random heap data.
Drive wiper component that overwrites the beginning of drives (e.g., 132MB/1.5MB) with random heap-sourced data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.