{
  "id": "case-sony-pictures",
  "slug": "sony-pictures-destructive-wiper",
  "title": "Sony Pictures Entertainment Destructive Wiper Attack",
  "summary": "North Korean state-sponsored operators infiltrated Sony Pictures Entertainment, deploying destructive Shamoon/Destover wipers that permanently erased thousands of servers and workstations, exfiltrating terabytes of unreleased films, employee SSNs, and executive emails.",
  "case_number": "2:18-cr-00569",
  "court": "U.S. District Court for the Central District of California",
  "district": "C.D. Cal.",
  "country": "United States",
  "opened_at": "2014-11-24",
  "status": "charged",
  "victim_sector": "Entertainment & Media",
  "victim_country": "United States",
  "loss_amount_usd": 100000000,
  "loss_amount_note": "Direct forensic investigation, legal fees, and canceled theatrical releases.",
  "first_seen_at": "2014-09-01T00:00:00Z",
  "last_updated_at": "2026-10-02T10:00:00Z",
  "actor_slug": "lazarus-group",
  "defendant_slugs": [
    "park-jin-hyok"
  ],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1485",
      "evidence_excerpt": "The Destover wiper module executed raw disk write calls to overwrite the Master Boot Record and partition tables, followed by automated reboots that rendered operating systems unbootable.",
      "evidence_locator": "DOJ Criminal Complaint \u00b6 44, Page 32",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "DOJ Criminal Complaint: U.S. v. Park Jin Hyok",
      "source_url": "https://www.justice.gov/opa/pr/north-korean-regime-backed-programmer-charged-conspiracy-conduct-multiple-cyberattacks-and",
      "technique_name": "Data Destruction",
      "tactic": "Impact"
    },
    {
      "technique_id": "T1566.002",
      "evidence_excerpt": "Adversaries sent targeted spearphishing messages to Sony employees via email and social networks containing malicious links masquerading as secure document shares.",
      "evidence_locator": "DOJ Criminal Complaint \u00b6 27, Page 19",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "DOJ Criminal Complaint",
      "source_url": "https://www.justice.gov/opa/pr/north-korean-regime-backed-programmer-charged-conspiracy-conduct-multiple-cyberattacks-and",
      "technique_name": "Spearphishing Link",
      "tactic": "Initial Access"
    },
    {
      "technique_id": "T1003",
      "evidence_excerpt": "Operators deployed custom credential dumpers to extract Active Directory hashes and plaintext administrative passwords from compromised system memory.",
      "evidence_locator": "FBI Flash Alert: Destructive Malware",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "FBI Flash Report",
      "source_url": "https://www.cisa.gov",
      "technique_name": "OS Credential Dumping",
      "tactic": "Credential Access"
    },
    {
      "technique_id": "T1567",
      "evidence_excerpt": "The conspirators staged gigabytes of executive email archives and unreleased video assets on staging servers before transmitting them to public leak distribution networks.",
      "evidence_locator": "DOJ Criminal Complaint \u00b6 52, Page 38",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "DOJ Criminal Complaint",
      "source_url": "https://www.justice.gov",
      "technique_name": "Exfiltration Over Web Service",
      "tactic": "Exfiltration"
    }
  ],
  "events": [
    {
      "event_type": "incident",
      "event_date": "2014-11-24",
      "description": "Destover wiper detonates across Sony Pictures network, displaying red skull screens on workstations."
    },
    {
      "event_type": "advisory",
      "event_date": "2014-12-19",
      "description": "FBI formally attributes the destructive intrusion to the government of North Korea."
    },
    {
      "event_type": "indictment",
      "event_date": "2018-09-06",
      "description": "U.S. Department of Justice unseals criminal complaint charging Lazarus operative Park Jin Hyok."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Infiltration of Sony Pictures Entertainment internal network via targeted spearphishing emails carrying malicious attachments, credential dumping, and compromised service accounts.",
    "blast_radius": "Destruction of thousands of workstations and servers using the Shamoon-derivative wiper WIPALL (Destover), unreleased films and scripts leaked publicly, 47,000 employee Social Security numbers and executive emails disclosed, resulting in an estimated $35M+ in remediation expenses and major geopolitical sanctions against North Korea.",
    "kill_chain": [
      {
        "phase": "Initial Infiltration",
        "title": "Targeted Spearphishing & Credential Theft",
        "description": "Lazarus Group operatives targeted Sony systems administrators and executives with spearphishing lures, harvesting domain credentials and establishing an initial footholds.",
        "technical_artifacts": [
          "Malicious PDF/macro attachments",
          "Harvested domain credentials"
        ],
        "mitre_technique_id": "T1566.001"
      },
      {
        "phase": "Discovery & Privilege Escalation",
        "title": "Active Directory Compromise & Password Scraping",
        "description": "Adversaries mapped internal network architecture, targeted domain controllers, and extracted passwords from plaintext files and LSASS memory.",
        "technical_artifacts": [
          "LSASS memory dumper",
          "Plaintext password files",
          "Active Directory queries"
        ],
        "mitre_technique_id": "T1003"
      },
      {
        "phase": "Lateral Movement",
        "title": "Scheduled Task & Service Distribution",
        "description": "Operatives utilized legitimate administrative privileges and NetBIOS/WMI to distribute batch scripts and scheduled tasks across corporate hosts.",
        "technical_artifacts": [
          "at.exe scheduled tasks",
          "WMI command execution",
          "NetBIOS shares"
        ],
        "mitre_technique_id": "T1053.005"
      },
      {
        "phase": "Data Exfiltration",
        "title": "Mass Staging & Multi-Gigabyte Exfiltration",
        "description": "Terabytes of unreleased movies, internal executive correspondence, and employee PII were staged and exfiltrated to adversary-controlled C2 servers.",
        "technical_artifacts": [
          "Compressed archives",
          "Encrypted C2 exfiltration channels"
        ],
        "mitre_technique_id": "T1567"
      },
      {
        "phase": "Destructive Impact",
        "title": "Destructive WIPALL / Destover Detonation",
        "description": "The WIPALL wiper overwrote Master Boot Records (MBR), corrupted disk partition tables, and deleted system files before displaying red skeleton ransom imagery.",
        "technical_artifacts": [
          "WIPALL / Destover payload",
          "MBR overwrite routine",
          "Reboot command"
        ],
        "mitre_technique_id": "T1485"
      }
    ],
    "defensive_takeaways": [
      "Disallow storage of plaintext administrative credentials across shared enterprise storage and local folders.",
      "Implement central endpoint detection capable of blocking raw disk access and MBR alteration.",
      "Isolate critical corporate file servers from general workstation access.",
      "Enforce multi-factor authentication across all remote access entry points."
    ]
  }
}