Description
[Meteor](https://attack.mitre.org/software/S0688) is a wiper that was used against Iranian government organizations, including Iranian Railways, the Ministry of Roads, and Urban Development systems, in July 2021. [Meteor](https://attack.mitre.org/software/S0688) is likely a newer version of similar wipers called Stardust and Comet that were reportedly used by a group called "Indra" since at least 2019 against private companies in Syria.(Citation: Check Point Meteor Aug 2021)
External References
Techniques Used by This Malware
- T1036.004 — Masquerade Task or Service
- T1047 — Windows Management Instrumentation
- T1053.005 — Scheduled Task
- T1057 — Process Discovery
- T1059.001 — PowerShell
- T1059.003 — Windows Command Shell
- T1070.001 — Clear Windows Event Logs
- T1070.004 — File Deletion
- T1082 — System Information Discovery
- T1105 — Ingress Tool Transfer
- T1106 — Native API
- T1484.001 — Group Policy Modification
- T1485 — Data Destruction
- T1489 — Service Stop
- T1490 — Inhibit System Recovery
- T1491.001 — Internal Defacement
- T1518.001 — Security Software Discovery
- T1531 — Account Access Removal
- T1562.001 — Disable or Modify Tools
- T1564.003 — Hidden Window