Killdisk

Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 11:27:56

Context

In 2015 the BlackEnergy malware contained a component called KillDisk. KillDisk's main functionality is to overwrite files with random data, rendering the OS unbootable.

Detection coverage

  • 2 YARA rules

Used by threat actors

  • 2015 Ukraine Electric Power Attack (campaign)

Detection rules

  • MALPEDIA_Win_Lazarus_Killdisk_Auto (yara-rule)
  • MALPEDIA_Win_Killdisk_Auto (yara-rule)

External references