Killdisk
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 11:27:56
Context
In 2015 the BlackEnergy malware contained a component called KillDisk. KillDisk's main functionality is to overwrite files with random data, rendering the OS unbootable.
Detection coverage
- 2 YARA rules
Used by threat actors
- 2015 Ukraine Electric Power Attack (campaign)
Detection rules
- MALPEDIA_Win_Lazarus_Killdisk_Auto (yara-rule)
- MALPEDIA_Win_Killdisk_Auto (yara-rule)