StoneDrill is a Windows malware family best known for its destructive wiper capability and its overlap with Iranian intrusion activity. It has been associated with operations linked to Elfin, also tracked as APT33, and has been discussed alongside Shamoon due to similar destructive tradecraft. StoneDrill combines espionage and access-enabling functions with a destructive component capable of wiping the master boot record, rendering infected systems unbootable.
Observed functionality includes opening a backdoor on compromised hosts, downloading additional files, taking screenshots, checking for installed antivirus and antimalware products, obtaining the victim system’s current date and time, and querying the Windows Registry to identify the default browser. It has also used VBScript components during different stages of execution, leveraged WMIC to run tasks, and employed anti-emulation techniques to hinder automated analysis. A notable execution and evasion characteristic is direct payload injection into the memory of the victim’s preferred browser process.
StoneDrill has been reported deleting temporary files after they have served their purpose, indicating cleanup and anti-forensic behavior. The malware’s combination of browser-process injection, security-tool discovery, scripting support, and destructive disk-wiping functionality makes it a hybrid intrusion tool suited for both covert access and disruptive operations. Reporting has placed it in campaigns affecting organizations in the Middle East, particularly in contexts involving Iranian state-linked threat activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Symantec has the following protection in place to protect customers against Elfin attacks: ... Trojan.Stonedrill ...
Wiper Malware : StoneDrill , similar to Shamoon2 malware, was used in some campaigns.
MAGNALLIUM ... CAPABILITIES: STONEDRILL wiper, variants of TURNEDUP malware
15 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware using WMI/WMIC/wmiexec for remote execution, lateral movement, discovery, persistence, and administrative actions; e.g., 'APT41 used WMI in several ways, including for execution of commands via WMIEXEC as well as for persistence via PowerSploit' and 'Scattered Spider used Windows Management Instrumentation (WMI) to move laterally via Impacket.'
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
The content repeatedly describes adversaries and malware injecting code, shellcode, DLLs, or payloads into legitimate processes such as svchost.exe, explorer.exe, iexplore.exe, wuauclt.exe, lsass.exe, and browser processes.
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
Agent Tesla has the ability to perform anti-sandboxing and anti-virtualization checks. Bisonal can check to determine if the compromised system is running on VMware. Bumblebee has the ability to perform anti-virtualization checks. CozyCar will check to ensure it is not being executed inside a virtual machine or a known malware analysis sandbox environment. Metamorfo has embedded a "vmdetect.exe" executable to identify virtual machines at the beginning of execution. RTM can detect if it is running within a sandbox or other virtualized analysis environment. Saint Bear contains several anti-analysis and anti-virtualization checks.
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information.
The content repeatedly describes malware and threat actors collecting the current date, time, or time zone from victim systems, including examples such as "The net time command can be used... to determine the local or remote system time" and commands like "net time \\hostname" and "w32tm /tz".
Agent Tesla has the ability to perform anti-sandboxing and anti-virtualization checks. Bisonal can check to determine if the compromised system is running on VMware. Bumblebee has the ability to perform anti-virtualization checks. CozyCar will check to ensure it is not being executed inside a virtual machine or a known malware analysis sandbox environment. Metamorfo has embedded a "vmdetect.exe" executable to identify virtual machines at the beginning of execution. RTM can detect if it is running within a sandbox or other virtualized analysis environment. Saint Bear contains several anti-analysis and anti-virtualization checks.
"StoneDrill can wipe the accessible physical or logical drives of the infected machine."
APT37 has access to destructive malware that is capable of overwriting a machine's Master Boot Record (MBR). APT38 has used a custom MBR wiper named BOOTWRECK to render systems inoperable. CaddyWiper has the ability to destroy information about a physical drive's partitions including the MBR, GPT, and partition entries.
46 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware listed by Symantec among protections for Elfin attacks; historically associated with destructive activity.
Wiper malware used in some campaigns; described as similar to Shamoon2.
Destructive malware that injects its payload into browser process memory.
Uses several VBS scripts throughout its lifecycle.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.