Destover

Description

(Kaspersky) The most interesting aspects of the destructive functionality of the malware are related to the selection and storage/delivery of the drivers that are now used repeatedly in these kinds of sabotage attacks.

The Destover droppers install and run EldoS RawDisk drivers to evade NTFS security permissions and overwrite disk data and the MBR itself. There are implications for data recovery in this. In the case of the DarkSeoul malware, the overwritten data could be restored using a method similar to the restoration of the Shamoon ‘destroyed’ data. Destover data recovery is likely to be the same.

Names

Name
Destover
Sierras

Category

Malware

Type

  • Wiper

Information

Malpedia

Other Information

Uuid

b23d9046-7958-4dc8-9cb6-2c8b7386b8bc

Last Card Change

2020-05-14