Destover
Description
(Kaspersky) The most interesting aspects of the destructive functionality of the malware are related to the selection and storage/delivery of the drivers that are now used repeatedly in these kinds of sabotage attacks.
The Destover droppers install and run EldoS RawDisk drivers to evade NTFS security permissions and overwrite disk data and the MBR itself. There are implications for data recovery in this. In the case of the DarkSeoul malware, the overwritten data could be restored using a method similar to the restoration of the Shamoon ‘destroyed’ data. Destover data recovery is likely to be the same.
Names
Name |
---|
Destover |
Sierras |
Category
Malware
Type
- Wiper
Information
- https://securelist.com/destover/67985/
- https://securingtomorrow.mcafee.com/mcafee-labs/analyzing-operation-ghostsecret-attack-seeks-to-steal-data-worldwide/
Malpedia
Other Information
Uuid
b23d9046-7958-4dc8-9cb6-2c8b7386b8bc
Last Card Change
2020-05-14