THREAT ACTOR WEAPONRY

Threat Arsenal & Malware Profiles

Detailed technical directory of landmark malware strains, destructive wipers, and cybercrime payloads documented in DOJ indictments, CISA technical alerts, and forensic reverse engineering reports.

Key Facts

  • Catalog of primary destructive wipers, ICS sabotage code, and ransomware families cited in federal indictments.
  • Technical reverse engineering profiles detail execution mechanics, anti-analysis, and forensic indicators.
  • Cross-referenced against MITRE ATT&CK techniques and real prosecution evidentiary exhibits.
  • Focuses on nation-state military tools (GRU, SVR) and high-impact cybercrime syndicates.

NotPetya / EternalPetya

Destructive Wiper / False Ransomware
Author: Sandworm (Russian GRU Unit 74455)
Active Since: June 2017

Irreversible MBR overwriting and raw NTFS file table destruction. Caused over $10B in global collateral damages.

Initial Infection Vector: Hijacked M.E.Doc Accounting Software Update Mechanism
Propagation & Lateral Movement: EternalBlue (MS17-010) & EternalRomance SMB Exploitation + PsExec lateral movement
Forensic Highlights: Presents a ransom note demanding $300 in Bitcoin, but intentionally corrupts the Master File Table (MFT) with pseudo-random keys, making decryption cryptographically impossible.
Documented Attack Library Cases:

KillDisk / BlackEnergy 3

Industrial Control System (ICS) Wiper
Author: Sandworm (Russian GRU Unit 74455)
Active Since: December 2015

Disconnected 30 substations in Western Ukraine, cutting electrical power to 225,000 citizens in mid-winter.

Initial Infection Vector: Spear-phishing emails containing malicious Microsoft Office macros
Propagation & Lateral Movement: Direct workstation traversal to SCADA/EMS control systems; firmware wiping of serial-to-Ethernet converters
Forensic Highlights: Overwrites file system sectors with fixed patterns (such as 0x00 or repetitive strings), kills critical operating system processes, and flashes malicious firmware onto remote terminal units (RTUs).
Documented Attack Library Cases:

AcidRain / AcidPour

Embedded Linux MTD Flash Wiper
Author: Sandworm (Russian GRU Unit 74455)
Active Since: February 2022

Bricked tens of thousands of satellite terminals across Europe and knocked out 5,800 German wind turbines on the morning of the Russian invasion of Ukraine.

Initial Infection Vector: Exploitation of misconfigured VPN concentrators on KA-SAT ground management segment
Propagation & Lateral Movement: Direct execution on satellite broadband modems (Viasat SurfBeam 2)
Forensic Highlights: Recursive directory traversal and overwrite of raw flash memory blocks (/dev/mtd*, /dev/sda, /dev/mmcblk) using memcopy loops, rendering satellite modems permanently unbootable.
Documented Attack Library Cases:

SUNBURST (Solorigate)

Supply Chain Backdoor DLL
Author: Cozy Bear (APT29 / Russian SVR)
Active Since: March 2020 (Uncovered Dec 2020)

Stealthy espionage campaign targeting U.S. Treasury, Dept of Homeland Security, and Fortune 500 tech firms.

Initial Infection Vector: Compromised Orion build system injecting code into SolarWinds.Orion.Core.BusinessLayer.dll
Propagation & Lateral Movement: Digitally signed product updates distributed to 18,000 customers worldwide
Forensic Highlights: Dormant execution timer (waited up to two weeks before connecting), domain name generation algorithms (DGA) mimicking normal Orion telemetry, in-memory execution of second-stage payloads.
Documented Attack Library Cases:

BlackPOS / Kaptoxa

Point-of-Sale (POS) RAM Memory Scraper
Author: Rinat Shaikhov & Cybercrime Ring
Active Since: Late 2013

Exfiltrated 40M payment cards from Target and 56M payment cards from Home Depot.

Initial Infection Vector: Stolen third-party HVAC and billing vendor credentials via external portals
Propagation & Lateral Movement: PsExec and batch scripts across corporate internal subnets to cash register terminals
Forensic Highlights: Hooks POS software memory processes (POS.exe) to intercept unencrypted Track 1 and Track 2 magnetic stripe card data during the brief millisecond window before tokenization.
Documented Attack Library Cases:

ALPHV / BlackCat Ransomware

Rust-Based Multi-Platform Ransomware
Author: ALPHV Gang / FIN7 Descendants
Active Since: November 2021

Crippled Change Healthcare ($3.3B loss), MGM Resorts ($100M loss), and dozens of enterprise targets.

Initial Infection Vector: Stolen credentials, unpatched edge VPNs, Citrix portals, helpdesk social engineering
Propagation & Lateral Movement: Cobalt Strike, PsExec, and custom PowerShell scripts disabling volume shadow copies
Forensic Highlights: Written entirely in Rust for cross-platform execution (Windows, Linux, VMware ESXi). Features multi-threaded encryption using ChaCha20 or AES-Bcrypt, automated ESXi VM termination via esxcli.
Documented Attack Library Cases: