Killdisk
Overview
Executive Summary
KillDisk is a highly destructive malware family—specifically, a wiper—designed with the sole intention of rendering infected systems completely unbootable and permanently destroying data. It gained international notoriety for its deployment in coordinated cyber-kinetic attacks against critical infrastructure, most notably during the December 2015 attack on the Ukrainian power grid attributed to the Russian state-sponsored group known as Sandworm (Unit 74455).Technical Architecture and Destructive Capabilities
KillDisk is typically deployed during the final stages of a targeted attack, often after threat actors have successfully exfiltrated sensitive data and achieved widespread lateral movement across an Industrial Control System (ICS) or enterprise network. Upon execution, KillDisk operates with elevated privileges to systematically destroy the host:- MBR/VBR Destruction: The malware directly targets the physical sectors of the hard drive, explicitly overwriting the Master Boot Record (MBR) and the Volume Boot Record (VBR) with randomized data. This instantly renders the operating system unbootable.
- File Overwriting: It traverses the file system, targeting specific file extensions (databases, configuration files, documents) and overwriting their contents with null bytes or random characters before deleting them, thwarting basic data recovery efforts.
- Event Log Wiping: To hinder forensic investigations and incident response, KillDisk systematically deletes Windows Event Logs and system backups prior to initiating its destructive routine.
Threat Impact
The deployment of KillDisk is an act of cyber sabotage. Its impact is catastrophic, leading to total data loss, severe operational downtime, and potentially physical consequences when deployed against critical infrastructure and SCADA systems.Defense and Resilience Strategies
- Offline Backups: The only reliable defense against a successful wiper attack is a robust, isolated backup strategy. Implement the 3-2-1 backup rule, ensuring that at least one backup copy is stored completely offline and immutable (air-gapped).
- Least Privilege and Network Segmentation: Strictly enforce the principle of least privilege, particularly for accounts managing ICS and critical servers. Segment networks to prevent lateral movement from the corporate IT environment to the operational technology (OT) environment.
- Behavioral EDR: Deploy advanced EDR solutions configured to block unauthorized attempts to access raw disk sectors or rapidly delete volume shadow copies.
Known aliases
Threat reports may refer to this family under multiple names:
MITRE ATT&CK Techniques
This family has been observed using the following ATT&CK techniques: T1485 T1561.001 T1561.002 T1070.001
Generated Detections (Boilerplate)
These YARA and Sigma rules are auto-generated based on the family name and aliases. They must be heavily tuned before deployment in a production environment.
YARA Rule
rule MALWARE_WIN_KILLDISK {
meta:
description = "Detects Killdisk (ransomware)"
author = "SystemHelpdesk Boilerplate Generator"
date = "2026-07-06"
strings:
$s1 = "killdisk" ascii wide nocase
$s2 = "wiper.killdisk" ascii wide nocase
$s3 = "trojan.killdisk" ascii wide nocase
$s4 = "sandworm wiper" ascii wide nocase
condition:
uint16(0) == 0x5a4d and any of them
}Sigma Rule
title: Suspicious Killdisk Activity
id: 78f026e755123b87718c141a202e8b54
status: experimental
description: Detects generic indicators of the killdisk malware family.
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith:
- '\cmd.exe'
- '\powershell.exe'
CommandLine|contains:
- "*killdisk*"
- "*wiper.killdisk*"
- "*trojan.killdisk*"
- "*sandworm wiper*"
condition: selection
level: mediumReferences & External Analysis
- Search "killdisk" on VirusTotal (External Analysis)
Frequently Asked Questions
How do I remove the Killdisk Ransomware from Windows?
Manual removal of Killdisk is highly discouraged as it may leave persistence mechanisms intact. We recommend disconnecting the device from the internet and utilizing a professional incident response service or enterprise-grade EDR software to conduct a full forensic sweep.
Is Killdisk a virus or a Ransomware?
Killdisk is classified as a Ransomware. Unlike traditional viruses that infect files, modern malware like Killdisk typically operates as a standalone payload designed to compromise systems, steal data, or deploy secondary stage implants.
What are the main symptoms of a Killdisk infection?
Symptoms of Killdisk can include unexpected system slowness, unauthorized outbound network traffic to unknown IP addresses, disabled security software, and suspicious background processes running from AppData or Temp directories.
Related Families (Category: ransomware)
Explore other malware families in the same category:
Protect Your Network Against Ransomwares
Want to prevent Killdisk and similar threats from compromising your organization? Read our comprehensive defensive guide: Ransomware Protection Guide.
Machine-readable
Get this profile as JSON: https://jordan123234-malware-families-explorer.static.hf.space/api/killdisk.json
Ecosystem & Interactive Environments
This profile is part of the Malware Families Catalog, a public dataset of 2,899 malware families. The catalog is also published across our ecosystem: Hugging Face, Kaggle, Zenodo, Replit, StackBlitz, CodeSandbox, and CodePen.