#Destover
Malware/Tool
Destover is destructive Windows malware used in the November 2014 intrusion at Sony Pictures Entertainment and linked through technical indicators to earlier attacks against South Korean targets. Its wiper can overwrite disk data and the master boot record, using EldoS RawDisk drivers to bypass NTFS security permissions and directly damage storage, complicating recovery. Some samples shared a command-and-control server with a Volgmer variant used against South Korean targets, suggesting common operators; Volgmer served reconnaissance and download functions in limited attacks. Reporting connects the broader activity to the DarkSeoul or Silent Chollima threat complex and notes suspected North Korean involvement, while acknowledging uncertainty about the operators' identity.
-
4
Tagged Reports
-
4
Unique Authors
-
3,256
Active Days