TACTIC: IMPACT
Data Destruction (T1485): real cases
MITRE Definition ↗ Adversaries irreversibly overwrite storage media and files to destroy data rather than extort ransoms.
Key Facts
Technique ID
T1485
Impact
Mapped Cases
5
Primary sources
Related Laws
4
Criminal statutes
- ATT&CK Technique Identifier: T1485.
- Tactical Phase: Impact.
- Substantiated in 5 primary court prosecution cases.
- Every associated case includes verbatim evidentiary excerpts from indictments or sworn affidavits.
Verified Evidentiary Case Records
U.S. v. Andrienko et al. (Sandworm / GRU Unit 74455)
fugitive 2020-10-15
Primary Source Evidence Excerpt: Indictment ¶ 44, Page 22
"The conspirators deployed the NotPetya malware, designed to irreversibly encrypt and destroy victim computer records worldwide while masquerading as ransomware."
U.S. District Court for the Western District of Pennsylvania
View full case dossier →
U.S. v. Park Jin Hyok (Lazarus Group / Chosun Expo)
fugitive 2018-06-08
Primary Source Evidence Excerpt: Criminal Complaint ¶ 42, Page 27
"The Sony Pictures attack used the Destover wiper to destroy master boot records and overwrite hard drives, rendering thousands of workstations permanently inoperable."
U.S. District Court for the Central District of California
View full case dossier →
U.S. v. IRGC Actors (CyberAv3ngers Critical Infrastructure Attacks)
fugitive 2024-09-24
Primary Source Evidence Excerpt: Indictment ¶ 18, Page 9
"Attackers defaced screen displays on industrial pressure monitoring stations with anti-Israel political slogans and halted remote pump regulation."
U.S. District Court for the Western District of Pennsylvania
View full case dossier →
Operation Olympic Games (Stuxnet Industrial SCADA Cyberweapon)
uncharged 2010-06-17
Primary Source Evidence Excerpt: CISA Industrial Control Systems Advisory ICSA-10-272-01
"The worm intercepted Siemens Step7 communications with programmable logic controllers (PLCs), secretly overriding centrifuge rotational frequencies while transmitting recorded normal telemetry back to control room displays."
U.S. Federal Executive Attribution
View full case dossier →
Saudi Aramco Shamoon Wiper Attack (Cutting Sword of Justice)
uncharged 2012-08-15
Primary Source Evidence Excerpt: CISA Alert TA12-240A: Shamoon Malware
"The Wiper module contained an embedded EldoS RawDisk driver to bypass Windows operating system write protection, directly overwriting raw sector bytes of the Master Boot Record with image data."
U.S. Intelligence Community Attribution
View full case dossier →
Commonly Charged Criminal Statutes
18 U.S.C. § 1030(a)(2)
Unauthorized Access to Obtain Protected Information
Prohibits intentionally accessing a computer without authorization or exceeding authorized access to obtain financial, government, or protected computer records.
18 U.S.C. § 1030(a)(5)(A)
Intentional Damage to a Protected Computer
Prohibits knowingly causing the transmission of a program, information, code, or command that intentionally causes damage without authorization to a protected computer.
18 U.S.C. § 1030(a)(7)
Extortion in Connection with Computers
Prohibits transmitting in interstate or foreign commerce threats to cause damage to a protected computer or obtain confidential information with intent to extort money or value.
18 U.S.C. § 1030(b)
Conspiracy to Commit Computer Fraud
Punishes any person who conspires to commit or attempts to commit any computer fraud offense under section 1030.