MultiLayer Wiper is a destructive Windows wiper designed to impede recovery and maximize system disruption through multi-stage file and disk damage, anti-forensics, and recovery inhibition. It contains embedded components named MultiList and MultiWip in its resource section, drops and executes those payloads at runtime, and deletes them afterward. The malware deletes files on network drives while corrupting and overwriting locally stored files with random data, alters deleted-file path metadata to complicate recovery, and manipulates timestamps of overwritten files to anti-forensic values associated with different filesystem types. It also clears file system cache memory through a batch-scripted invocation of a Windows API export as an anti-analysis and anti-forensics measure.
To inhibit restoration, MultiLayer Wiper removes the Volume Shadow Copy service and deletes existing shadow copies. It further damages host recoverability by opening the primary physical drive directly and wiping the first 512 bytes, removing the boot sector and rendering systems unbootable. The malware creates a malicious scheduled task that launches a batch file to remove Windows Event Logs, then reboots the system after destructive actions to further hinder recovery and investigation. The combination of file destruction, boot-sector wiping, log removal, timestamp manipulation, and shadow-copy deletion makes MultiLayer Wiper a purpose-built impact tool focused on sabotaging Windows endpoints and accessible network storage.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
MultiLayer Wiper removes the Volume Shadow Copy (VSS) service from infected devices along with all present shadow copies.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
During Frankenstein, the threat actors ran a command script to set up persistence as a scheduled task named "WinUpdate". MultiLayer Wiper uses a batch script launched via a scheduled task to delete Windows Event Logs. Tarrask may abuse the Windows schtasks command-line tool to create "hidden" scheduled tasks.
APT1 has used the Windows command shell to execute commands, and batch scripting to automate execution. Blue Mockingbird has used batch script files to automate execution and deployment of payloads. During HomeLand Justice, threat actors used Windows batch files for persistence and execution.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
During Frankenstein, the threat actors ran a command script to set up persistence as a scheduled task named "WinUpdate". MultiLayer Wiper uses a batch script launched via a scheduled task to delete Windows Event Logs. Tarrask may abuse the Windows schtasks command-line tool to create "hidden" scheduled tasks.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
During Frankenstein, the threat actors ran a command script to set up persistence as a scheduled task named "WinUpdate". MultiLayer Wiper uses a batch script launched via a scheduled task to delete Windows Event Logs. Tarrask may abuse the Windows schtasks command-line tool to create "hidden" scheduled tasks.
Many examples describe post-intrusion cleanup, anti-forensics, and removal of artifacts such as logs, scripts, malware components, scheduled tasks, registry keys, and temporary files.
The content repeatedly describes threat actors and malware deleting files, tools, scripts, logs, droppers, staged data, and artifacts from compromised systems to cover tracks, remove evidence, or self-delete.
APT28 has performed timestomping on victim files. APT29 has used timestomping to alter the Standard Information timestamps on their web shells to match other files in the same directory. APT32 has used scheduled task raw XML with a backdated timestamp... APT38 has modified data timestamps to mimic files that are in the same folder on a compromised host.
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
“Sandworm Team deployed CaddyWiper…to wipe files…along with mapped drives, and physical drive partitions… AcidPour…perform an in-depth wipe…through either data overwrite or calling various IOCTLS… AcidRain performs an in-depth wipe… Apostle…data destruction tool… writes random data… resizing… deleting… BlackEnergy 2 contains a ‘Destroy’ plug-in… overwriting file contents… HermeticWiper… recursively wipe folders and files… Industroyer’s data wiper module clears registry keys and overwrites… KillDisk deletes system files to make the OS unbootable… Shamoon attempts to overwrite operating system files and disk structures… WhisperGate… corrupt files by overwriting…”
Akira will delete system volume shadow copies via PowerShell commands. Avaddon deletes backups and shadow copies using native system tools. Babuk has the ability to delete shadow volumes using vssadmin.exe delete shadows /all /quiet. BlackCat can delete shadow copies using vssadmin.exe delete shadows /all /quiet and wmic.exe Shadowcopy Delete; it can also modify the boot loader using bcdedit /set {default} recoveryenabled No.
"AcidPour includes functionality to reboot the victim system following wiping actions..."; "AcidRain reboots the target system once the various wiping processes are complete"; "Apostle reboots the victim machine following wiping"; "APT37 ... issue the command shutdown /r /t 1 to reboot a system after wiping its MBR"; "APT38 ... BOOTWRECK ... initiate a system reboot after wiping the victim's MBR"; "Black Basta ... used ShellExecuteA to shut down and restart"; "DarkGate ... used the shutdown command"; "HermeticWiper can initiate a system shutdown"; "NotPetya will reboot the system one hour after infection"; "Shamoon will reboot the infected system once the wiping functionality has been completed"; "WhisperGate can shutdown ... through ... ExitWindowsEx"
APT37 has access to destructive malware that is capable of overwriting a machine's Master Boot Record (MBR). APT38 has used a custom MBR wiper named BOOTWRECK to render systems inoperable. CaddyWiper has the ability to destroy information about a physical drive's partitions including the MBR, GPT, and partition entries.
The content repeatedly describes threat actors and malware disabling or modifying security tools, EDR/AV, logging, firewall rules, integrity checkers, and security settings; e.g., 'Agrius used several mechanisms to try to disable security tools' and 'BlackByte disabled security tools such as Windows Defender and the Raccine anti-ransomware tool during operations.'
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Wiper malware that wipes the boot sector to inhibit system recovery.
Wiper malware that resets overwritten file timestamps to filesystem-specific baseline dates.
Wiper malware that contains two embedded binaries in its resources section, drops and executes them, then deletes them after execution.
Wiper that creates a scheduled task to launch a batch file and remove event logs.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.