US-CERT published technical details on the malware used in the destructive cyberattack against Sony Pictures, describing a multi-component toolset that targeted Microsoft Windows systems and spread laterally through SMB shares on port 445 using brute-force authentication. The malware suite included an SMB worm, a listening implant, a lightweight backdoor, a proxy tool, a destructive hard drive wiper, and a target cleaning utility. According to the alert, the tools enabled remote command execution, file transfer, firewall and UPnP manipulation, and reporting of successful compromises to command-and-control servers hosted across several countries.
The destructive components were designed to overwrite files, the master boot record, and portions of physical drives, leaving systems unusable or severely degraded until reboot in some Windows 7 environments. The disclosure came shortly after U.S. officials publicly attributed the Sony intrusion to North Korea, and followed earlier FBI warnings about the malware, which some vendors tracked as Destover. US-CERT also released malware hashes, filenames, C2 IP addresses, Snort signatures, and YARA rules, while urging organizations to strengthen backups, network segmentation, least-privilege controls, patching, and monitoring to reduce the risk of similar attacks and intellectual property loss.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
US-CERT released alert TA14-353A detailing the SMB worm toolset used in the Sony Pictures attack, including malware behavior, hashes, filenames, command-and-control IP addresses, Snort signatures, and YARA rules. The advisory also recommended mitigations such as backups, segmentation, least privilege, patching, and monitoring.
The FBI and President Obama publicly attributed the destructive cyberattack against Sony Pictures to North Korea. This attribution was reported as occurring shortly before US-CERT published its malware advisory.
Before the public US-CERT alert, the FBI circulated a flash memo to selected organizations warning about the malware associated with the Sony Pictures attack, which some security vendors referred to as Destover.
Cyber threat actors deployed a destructive malware toolset against Sony Pictures, including an SMB worm for lateral movement, backdoors, proxy capabilities, and disk-wiping components that overwrote files, master boot records, and parts of physical drives on Windows systems. The attack disrupted systems and risked loss of intellectual property.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.