WhiskeyAlfa is a Lazarus Group malware family with destructive disk-wiping functionality. The provided content states that Lazarus Group used WhiskeyAlfa to overwrite the first 64MB of every drive with a mix of static and random buffers. It also uses a similar process to wipe content in logical drives and then attempts to wipe every byte of every sector on every drive. The broader context associates WhiskeyAlfa with Lazarus Group destructive operations alongside WhiskeyBravo, WhiskeyDelta, and SHARPKNOT, including wiping disk contents, overwriting the MBR, and rendering systems unbootable. The content further notes Lazarus Group campaigns involving internal defacement after systems were rendered unbootable. High-confidence attribution in the provided material links WhiskeyAlfa to Lazarus Group; no additional infection vector, industry targeting, or specific IOC values are directly provided for WhiskeyAlfa itself.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Lazarus Group has used malware like WhiskeyAlfa to overwrite the first 64MB of every drive with a mix of static and random buffers.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
"Lazarus Group has used malware like WhiskeyAlfa to overwrite the first 64MB of every drive... attempt to wipe every byte of every sector on every drive."
Lazarus Group has used malware like WhiskeyAlfa to overwrite the first 64MB of every drive with a mix of static and random buffers... WhiskeyBravo can be used to overwrite the first 4.9MB of physical drives. WhiskeyDelta can overwrite the first 132MB or 1.5MB of each drive with random data from heap memory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Disk-wiping malware used by Lazarus to overwrite large portions of physical and logical drives.
Drive wiper that overwrites the beginning of physical drives (e.g., first 64MB) and attempts broader sector wiping.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.