Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
MalwareRansomwareUsed by 1 actor

DEADWOOD

DEADWOOD, also referred to as Detbosit, is a destructive wiper malware with reported but unconfirmed links to an Iranian threat group. It has been associated with the Iran-linked threat actor Agrius, which used it in destructive operations masquerading as ransomware against targets in the Middle East, including Israeli organizations beginning in 2020; the malware had also reportedly been used against a target in Saudi Arabia in 2019. DEADWOOD contains an embedded AES-encrypted payload labeled METADATA that provides configuration information for follow-on execution. It can set a timestamp to control when wiping begins, executing immediately if the configured timestamp is in the past. DEADWOOD can run as a Windows service and attempts to masquerade its service execution with benign-looking names such as ScDeviceEnums. Its destructive behavior includes overwriting files with random data and then deleting them, as well as opening each drive and writing zeroes to the first 512 bytes to delete the master boot record (MBR). It then sends the IOCTL_DISK_DELETE_DRIVE_LAYOUT control code to ensure the MBR is removed from the drive, rendering systems inoperable.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Mustang Panda

The attacks were carried out using DEADWOOD ( aka Detbosit), a wiper with unconfirmed links to an Iranian threat group.

via sentinelone labssentinelone.com
MITRE ATT&CK

Techniques & procedures

12 distinct techniques documented for this family, organized by ATT&CK tactic.

Execution

1 technique
T1569.002Service ExecutionEvidence1

Stealth

5 techniques
T1027Obfuscated Files or InformationEvidence3

The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.

T1027.009Embedded PayloadsEvidence2

Examples include 'contains an embedded, AES-encrypted resource named METADATA that contains configuration information for follow-on execution,' 'binary contains RC4 encrypted embedded scripts,' and 'initial payloads included encoded follow-on payloads located in the resources file of the first-stage loader.'

T1027.013Encrypted/Encoded FileEvidence2

Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'

T1036.004Masquerade Task or ServiceEvidence1
T1140Deobfuscate/Decode Files or InformationEvidence4

The content repeatedly describes malware and threat actors decoding, decrypting, deobfuscating, or unpacking payloads, strings, configuration data, commands, and C2 responses prior to execution or use.

Discovery

1 technique
T1124System Time DiscoveryEvidence1

Command and Control

1 technique
T1105Ingress Tool TransferEvidence1

It can be used to exfiltrate data or deploy additional malware.

Impact

4 techniques
T1485Data DestructionEvidence6

Initially engaged in espionage activity, Agrius deployed a set of destructive wiper attacks against Israeli targets, masquerading the activity as ransomware attacks.

T1531Account Access RemovalEvidence1
T1561.001Disk Content WipeEvidence2

APT37 has access to destructive malware that is capable of overwriting a machine's Master Boot Record (MBR). APT38 has used a custom MBR wiper named BOOTWRECK to render systems inoperable. CaddyWiper has the ability to destroy information about a physical drive's partitions including the MBR, GPT, and partition entries.

T1561.002Disk Structure WipeEvidence1
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping12

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.