Killdisk

Category: ransomware · Aliases: Wiper.KillDisk, Trojan.KillDisk, Sandworm Wiper · Sample count (EMBER 2018): 1 · Enrichment: insufficient_information · Updated: 2026-07-01T16:03:45Z
Category: RansomwareActor: Unknown / CybercriminalIndustry: Global / OpportunisticMotivation: Opportunistic

Overview

Executive Summary

KillDisk is a highly destructive malware family—specifically, a wiper—designed with the sole intention of rendering infected systems completely unbootable and permanently destroying data. It gained international notoriety for its deployment in coordinated cyber-kinetic attacks against critical infrastructure, most notably during the December 2015 attack on the Ukrainian power grid attributed to the Russian state-sponsored group known as Sandworm (Unit 74455).

Technical Architecture and Destructive Capabilities

KillDisk is typically deployed during the final stages of a targeted attack, often after threat actors have successfully exfiltrated sensitive data and achieved widespread lateral movement across an Industrial Control System (ICS) or enterprise network. Upon execution, KillDisk operates with elevated privileges to systematically destroy the host: Some later variants of KillDisk have incorporated a superficial ransomware component, demanding payment, but the underlying encryption routines are often flawed or intentionally designed to ensure data recovery is impossible regardless of payment.

Threat Impact

The deployment of KillDisk is an act of cyber sabotage. Its impact is catastrophic, leading to total data loss, severe operational downtime, and potentially physical consequences when deployed against critical infrastructure and SCADA systems.

Defense and Resilience Strategies

Known aliases

Threat reports may refer to this family under multiple names:

MITRE ATT&CK Techniques

This family has been observed using the following ATT&CK techniques: T1485 T1561.001 T1561.002 T1070.001

Generated Detections (Boilerplate)

These YARA and Sigma rules are auto-generated based on the family name and aliases. They must be heavily tuned before deployment in a production environment.

YARA Rule

rule MALWARE_WIN_KILLDISK {
    meta:
        description = "Detects Killdisk (ransomware)"
        author = "SystemHelpdesk Boilerplate Generator"
        date = "2026-07-06"
    strings:
        $s1 = "killdisk" ascii wide nocase
        $s2 = "wiper.killdisk" ascii wide nocase
        $s3 = "trojan.killdisk" ascii wide nocase
        $s4 = "sandworm wiper" ascii wide nocase
    condition:
        uint16(0) == 0x5a4d and any of them
}

Sigma Rule

title: Suspicious Killdisk Activity
id: 78f026e755123b87718c141a202e8b54
status: experimental
description: Detects generic indicators of the killdisk malware family.
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        Image|endswith:
            - '\cmd.exe'
            - '\powershell.exe'
        CommandLine|contains:
            - "*killdisk*"
            - "*wiper.killdisk*"
            - "*trojan.killdisk*"
            - "*sandworm wiper*"
    condition: selection
level: medium

References & External Analysis

Frequently Asked Questions

How do I remove the Killdisk Ransomware from Windows?

Manual removal of Killdisk is highly discouraged as it may leave persistence mechanisms intact. We recommend disconnecting the device from the internet and utilizing a professional incident response service or enterprise-grade EDR software to conduct a full forensic sweep.

Is Killdisk a virus or a Ransomware?

Killdisk is classified as a Ransomware. Unlike traditional viruses that infect files, modern malware like Killdisk typically operates as a standalone payload designed to compromise systems, steal data, or deploy secondary stage implants.

What are the main symptoms of a Killdisk infection?

Symptoms of Killdisk can include unexpected system slowness, unauthorized outbound network traffic to unknown IP addresses, disabled security software, and suspicious background processes running from AppData or Temp directories.

Related Families (Category: ransomware)

Explore other malware families in the same category:

Protect Your Network Against Ransomwares

Want to prevent Killdisk and similar threats from compromising your organization? Read our comprehensive defensive guide: Ransomware Protection Guide.

Need help with an active incident? Published by the SystemHelpdesk team.

Machine-readable

Get this profile as JSON: https://jordanricky1604-ship-it.github.io/malware-families-catalog/api/killdisk.json

Ecosystem & Interactive Environments

This profile is part of the Malware Families Catalog, a public dataset of 2,899 malware families. The catalog is also published across our ecosystem: Hugging Face, Kaggle, Zenodo, Replit, StackBlitz, CodeSandbox, and CodePen.