CASE DOSSIER charged

Sony Pictures Entertainment Destructive Wiper Attack

Docket: 2:18-cr-00569 Court: U.S. District Court for the Central District of California Opened: 2014-11-24 Sector: Entertainment & Media

Key Facts

Status
CHARGED
Legal disposition
Loss Amount
$100.0 million
Direct forensic investigation, legal fees, and canceled theatrical releases.
Techniques
4
Verified mappings
Defendants
1
Named in charges
  • Legal Status: CHARGED in U.S. District Court for the Central District of California.
  • Primary Target Sector: Entertainment & Media.
  • Documented Financial Loss: $100.0 million.
  • 4 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

North Korean state-sponsored operators infiltrated Sony Pictures Entertainment, deploying destructive Shamoon/Destover wipers that permanently erased thousands of servers and workstations, exfiltrating terabytes of unreleased films, employee SSNs, and executive emails.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Infiltration of Sony Pictures Entertainment internal network via targeted spearphishing emails carrying malicious attachments, credential dumping, and compromised service accounts.

Operational & Financial Fallout

Destruction of thousands of workstations and servers using the Shamoon-derivative wiper WIPALL (Destover), unreleased films and scripts leaked publicly, 47,000 employee Social Security numbers and executive emails disclosed, resulting in an estimated $35M+ in remediation expenses and major geopolitical sanctions against North Korea.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: CHARGED
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Infiltration of Sony Pictures Entertainment internal network via targeted spearphishing emails carrying malicious attachments, credential dumping, and compromised service accounts.

Adversary Kill Chain Flow

5 Documented Phases
1
Initial Infiltration Targeted Spearphishing & Credential Theft
MITRE ATT&CK T1566.001 →

Lazarus Group operatives targeted Sony systems administrators and executives with spearphishing lures, harvesting domain credentials and establishing an initial footholds.

Artifacts & Tooling: Malicious PDF/macro attachments Harvested domain credentials
2
Discovery & Privilege Escalation Active Directory Compromise & Password Scraping
MITRE ATT&CK T1003 →

Adversaries mapped internal network architecture, targeted domain controllers, and extracted passwords from plaintext files and LSASS memory.

Artifacts & Tooling: LSASS memory dumper Plaintext password files Active Directory queries
3
Lateral Movement Scheduled Task & Service Distribution
MITRE ATT&CK T1053.005 →

Operatives utilized legitimate administrative privileges and NetBIOS/WMI to distribute batch scripts and scheduled tasks across corporate hosts.

Artifacts & Tooling: at.exe scheduled tasks WMI command execution NetBIOS shares
4
Data Exfiltration Mass Staging & Multi-Gigabyte Exfiltration
MITRE ATT&CK T1567 →

Terabytes of unreleased movies, internal executive correspondence, and employee PII were staged and exfiltrated to adversary-controlled C2 servers.

Artifacts & Tooling: Compressed archives Encrypted C2 exfiltration channels
5
Destructive Impact Destructive WIPALL / Destover Detonation
MITRE ATT&CK T1485 →

The WIPALL wiper overwrote Master Boot Records (MBR), corrupted disk partition tables, and deleted system files before displaying red skeleton ransom imagery.

Artifacts & Tooling: WIPALL / Destover payload MBR overwrite routine Reboot command
Real-World Blast Radius & Operational Fallout

Destruction of thousands of workstations and servers using the Shamoon-derivative wiper WIPALL (Destover), unreleased films and scripts leaked publicly, 47,000 employee Social Security numbers and executive emails disclosed, resulting in an estimated $35M+ in remediation expenses and major geopolitical sanctions against North Korea.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Disallow storage of plaintext administrative credentials across shared enterprise storage and local folders.
✓ Implement central endpoint detection capable of blocking raw disk access and MBR alteration.
✓ Isolate critical corporate file servers from general workstation access.
✓ Enforce multi-factor authentication across all remote access entry points.

Procedural & Incident Timeline

2014-11-24 incident

Destover wiper detonates across Sony Pictures network, displaying red skull screens on workstations.

2014-12-19 advisory

FBI formally attributes the destructive intrusion to the government of North Korea.

2018-09-06 indictment

U.S. Department of Justice unseals criminal complaint charging Lazarus operative Park Jin Hyok.

Named Defendants & Operatives

Defendant Nationality Status Prison Term Restitution Notes
Park Jin Hyok Democratic People's Republic of Korea fugitive Pending None Lazarus Group computer programmer charged with WannaCry, Sony Pictures attack, and Bangladesh Bank heist.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1485 Data Destruction
Impact
"The Destover wiper module executed raw disk write calls to overwrite the Master Boot Record and partition tables, followed by automated reboots that rendered operating systems unbootable." DOJ Criminal Complaint ¶ 44, Page 32 reviewed
T1566.002 Spearphishing Link
Initial Access
"Adversaries sent targeted spearphishing messages to Sony employees via email and social networks containing malicious links masquerading as secure document shares." DOJ Criminal Complaint ¶ 27, Page 19 reviewed
T1003 OS Credential Dumping
Credential Access
"Operators deployed custom credential dumpers to extract Active Directory hashes and plaintext administrative passwords from compromised system memory." FBI Flash Alert: Destructive Malware reviewed
T1567 Exfiltration Over Web Service
Exfiltration
"The conspirators staged gigabytes of executive email archives and unreleased video assets on staging servers before transmitting them to public leak distribution networks." DOJ Criminal Complaint ¶ 52, Page 38 reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, Sony Pictures Entertainment Destructive Wiper Attack, No. 2:18-cr-00569 (U.S. District Court for the Central District of California 2014), https://cybercaselibrary.com/cases/sony-pictures-destructive-wiper/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/sony-pictures-destructive-wiper" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>