WhiskeyBravo is a Lazarus Group malware family with destructive disk-wiping functionality. The provided content states that it can overwrite the first 4.9 MB of physical drives, and places it within a broader Lazarus malware ecosystem that includes WhiskeyAlfa, WhiskeyDelta, SHARPKNOT, KiloAlfa, IndiaIndia, Sumarta, Torisma, and DRATzarus. The content further associates WhiskeyBravo with Lazarus Group destructive operations in which malware such as WhiskeyAlfa, WhiskeyBravo, WhiskeyDelta, and SHARPKNOT were used to wipe disk contents, overwrite the MBR, and render systems unbootable. High-confidence behavior directly attributed to WhiskeyBravo in the content is overwriting the initial 4.9 MB of physical drives, consistent with destructive impact against disk structures. The content does not provide a specific infection vector, platform scope beyond drive-level destructive behavior, or unique indicators of compromise for WhiskeyBravo itself.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
WhiskeyBravo can be used to overwrite the first 4.9MB of physical drives.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
"Lazarus Group has used malware like WhiskeyAlfa to overwrite the first 64MB of every drive... attempt to wipe every byte of every sector on every drive."
Lazarus Group has used malware like WhiskeyAlfa to overwrite the first 64MB of every drive with a mix of static and random buffers... WhiskeyBravo can be used to overwrite the first 4.9MB of physical drives. WhiskeyDelta can overwrite the first 132MB or 1.5MB of each drive with random data from heap memory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Lazarus disk wiper capable of overwriting the beginning of physical drives.
Drive wiper component used to overwrite the initial portion of physical drives (e.g., first 4.9MB).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.