DEADWOOD

MITRE ATT&CK: S1134 View on attack.mitre.org

Aliases: Agrius, DETBOSIT, SQLShred, DEADWOOD

First seen
2019-01-01 00:00:00
Malware type
wiper
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 13:21:12

Targeted industries: government-and-public-sector

Targeted regions: country_code:sa

Context

DEADWOOD is wiper malware written in C++ using Boost libraries. DEADWOOD was first observed in an unattributed wiping event in Saudi Arabia in 2019, and has since been incorporated into Agrius operations.

Detection coverage

  • 2 YARA rules
  • 88 Sigma rules

Malware & tools used

  • Disk Content Wipe (attack-pattern)
  • Embedded Payloads (attack-pattern)
  • Data Destruction (attack-pattern)
  • Masquerade Task or Service (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Service Execution (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • System Time Discovery (attack-pattern)
  • Account Access Removal (attack-pattern)
  • Disk Structure Wipe (attack-pattern)

Used by threat actors

Detection rules

  • DITEKSHEN_MALWARE_Win_DEADWOOD (yara-rule)
  • MALPEDIA_Win_Deadwood_Auto (yara-rule)

Reports & references

  • assets.sentinelone.com — Evol Agrius (report)
  • CrowdStrike — The Anatomy Of Wiper Malware Part 1 (report)
  • sentinelone.com — Sentinellabs From Wiper To Ransomware The Evolution Of Agrius (report)
  • ESET — Fantasy New Agrius Wiper Supply Chain Attack (report)
  • CrowdStrike — The Anatomy Of Wiper Malware Part 3 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Deadwood (report)
  • MITRE ATT&CK — S1134 (report)

External references