Sony Pictures Entertainment Destructive Wiper Attack
Key Facts
- Legal Status: CHARGED in U.S. District Court for the Central District of California.
- Primary Target Sector: Entertainment & Media.
- Documented Financial Loss: $100.0 million.
- 4 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Infiltration of Sony Pictures Entertainment internal network via targeted spearphishing emails carrying malicious attachments, credential dumping, and compromised service accounts.
Operational & Financial Fallout
Destruction of thousands of workstations and servers using the Shamoon-derivative wiper WIPALL (Destover), unreleased films and scripts leaked publicly, 47,000 employee Social Security numbers and executive emails disclosed, resulting in an estimated $35M+ in remediation expenses and major geopolitical sanctions against North Korea.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Infiltration of Sony Pictures Entertainment internal network via targeted spearphishing emails carrying malicious attachments, credential dumping, and compromised service accounts.
Adversary Kill Chain Flow
5 Documented PhasesLazarus Group operatives targeted Sony systems administrators and executives with spearphishing lures, harvesting domain credentials and establishing an initial footholds.
Adversaries mapped internal network architecture, targeted domain controllers, and extracted passwords from plaintext files and LSASS memory.
Operatives utilized legitimate administrative privileges and NetBIOS/WMI to distribute batch scripts and scheduled tasks across corporate hosts.
Terabytes of unreleased movies, internal executive correspondence, and employee PII were staged and exfiltrated to adversary-controlled C2 servers.
The WIPALL wiper overwrote Master Boot Records (MBR), corrupted disk partition tables, and deleted system files before displaying red skeleton ransom imagery.
Destruction of thousands of workstations and servers using the Shamoon-derivative wiper WIPALL (Destover), unreleased films and scripts leaked publicly, 47,000 employee Social Security numbers and executive emails disclosed, resulting in an estimated $35M+ in remediation expenses and major geopolitical sanctions against North Korea.
Procedural & Incident Timeline
Destover wiper detonates across Sony Pictures network, displaying red skull screens on workstations.
FBI formally attributes the destructive intrusion to the government of North Korea.
U.S. Department of Justice unseals criminal complaint charging Lazarus operative Park Jin Hyok.
Named Defendants & Operatives
| Defendant | Nationality | Status | Prison Term | Restitution | Notes |
|---|---|---|---|---|---|
| Park Jin Hyok | Democratic People's Republic of Korea | fugitive | Pending | None | Lazarus Group computer programmer charged with WannaCry, Sony Pictures attack, and Bangladesh Bank heist. |
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1485 | Data Destruction Impact | "The Destover wiper module executed raw disk write calls to overwrite the Master Boot Record and partition tables, followed by automated reboots that rendered operating systems unbootable." | DOJ Criminal Complaint ¶ 44, Page 32 | reviewed |
| T1566.002 | Spearphishing Link Initial Access | "Adversaries sent targeted spearphishing messages to Sony employees via email and social networks containing malicious links masquerading as secure document shares." | DOJ Criminal Complaint ¶ 27, Page 19 | reviewed |
| T1003 | OS Credential Dumping Credential Access | "Operators deployed custom credential dumpers to extract Active Directory hashes and plaintext administrative passwords from compromised system memory." | FBI Flash Alert: Destructive Malware | reviewed |
| T1567 | Exfiltration Over Web Service Exfiltration | "The conspirators staged gigabytes of executive email archives and unreleased video assets on staging servers before transmitting them to public leak distribution networks." | DOJ Criminal Complaint ¶ 52, Page 38 | reviewed |