Sierra(Alfa,Bravo, ...)

Aliases: Destover

First seen
2014-11-24 00:00:00
Malware type
wiper, backdoor
Family
Malware family
Profile updated
2026-07-07 12:46:47

Targeted industries: media-and-entertainment energy-and-utilities transportation-and-logistics

Targeted regions: country_code:us country_code:kr

Context

Sierra(Alfa,Bravo,...) is commonly known as Destover, a wiper malware used in targeted destructive cyber attacks. It was notably employed in the 2014 Sony Pictures hack attributed to North Korean actors, aimed at disrupting operations and causing reputational and financial damage.

Reports & references

  • web.archive.org — Swift Attackers Malware Linked More Financial Attacks (report)
  • Broadcom/Symantec — Attackers Target Dozens Global Banks New Malware (report)
  • blog.lexfo.fr — Lexfo Whitepaper The Lazarus Constellation (report)
  • brandefense.io — Lazarus Apt Group Apt38 (report)
  • Broadcom/Symantec — Wannacry Ransomware Attacks Show Strong Links Lazarus Group (report)
  • CrowdStrike — The Anatomy Of Wiper Malware Part 1 (report)
  • secureworks.com — Nickel Academy (report)
  • CrowdStrike — The Anatomy Of Wiper Malware Part 3 (report)
  • anomali.com — Evidence Of Stronger Ties Between North Korea And Swift Banking Attacks (report)
  • app.box.com — Xyyord0B806E6Or2Nh92Coxw2Areyyx4 (report)
  • baesystemsai.blogspot.de — Cyber Heist Attribution (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Sierras (report)
  • us-cert.gov — Ta14 353A (report)

External references