MultiLayer Wiper

MITRE ATT&CK: S1135 View on attack.mitre.org

Aliases: MultiLayer Wiper

Malware type
wiper
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 13:11:47

Targeted industries: energy-and-utilities government-and-public-sector

Context

MultiLayer Wiper is wiper malware written in .NET associated with Agrius operations. Observed samples of MultiLayer Wiper have an anomalous, future compilation date suggesting possible metadata manipulation.

Detection coverage

  • 337 Sigma rules

Malware & tools used

  • System Shutdown/Reboot (attack-pattern)
  • Indicator Removal (attack-pattern)
  • Clear Windows Event Logs (attack-pattern)
  • Stored Data Manipulation (attack-pattern)
  • File Deletion (attack-pattern)
  • Data Destruction (attack-pattern)
  • Embedded Payloads (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Inhibit System Recovery (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Timestomp (attack-pattern)
  • Disk Structure Wipe (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Disable or Modify Tools (attack-pattern)

Used by threat actors

Reports & references

  • Palo Alto Unit 42 — Agonizing Serpens Targets Israeli Tech Higher Ed Sectors (report)
  • MITRE ATT&CK — S1135 (report)

External references