RawDisk is a legitimate commercial Windows kernel driver from EldoS that provides low-level direct access to disks, partitions, files, and in some cases memory. Although designed for administrative, secure deletion, and forensic use cases, it has been repeatedly abused in destructive malware operations because it enables user-mode code to manipulate protected disk structures without requiring attackers to implement their own kernel component.
RawDisk is most notably associated with the Shamoon/Disttrack wiper family, where attackers used it to overwrite critical disk structures such as the master boot record and partition tables, as well as arbitrarily sized portions of disk content, rendering systems unbootable and unusable. It has also been referenced in destructive activity linked to the Sony Pictures intrusion. In these operations, the driver functioned as an enabler for disk wiping rather than as a standalone malicious family.
Its abuse is an early and prominent example of attackers leveraging trusted signed drivers for malicious purposes. In the Shamoon context, operators installed the driver and used it to write to protected system locations as part of large-scale destructive campaigns targeting organizations in Saudi Arabia. RawDisk therefore occupies an important place in the history of destructive Windows intrusions and in discussions of signed-driver abuse and bring-your-own-vulnerable-driver-adjacent tradecraft, even though the abuse in this case relied on intended functionality rather than exploitation of a software flaw.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A legitimate disk access driver abused in a BYOVD-style technique to enable direct disk manipulation and large-scale data destruction (used by Shamoon).
A disk access utility used as a component in Shamoon to overwrite disk structures such as the MBR and partitions.
A legitimate commercial disk access driver abused by Disttrack's wiper component to gain direct access to disks and partitions so it can overwrite protected system areas such as the MBR and partition tables.
A commercially available disk access/deletion utility whose driver was abused in destructive attacks to wipe data and hard drives.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.