WARNING: This technique will destroy the disk.
Uses UAC prompt to run CastOut will elevated privileges. CastOut is an MBR wiper that overwrite the first 512 bytes of \\.\PhysicalDrive0 with a string found in DarkSeoul (Lazarus/APT28) wipers.
To view this TTPs command, you must be logged in with a professional or enterprise license.
Destructive Master Boot Record (MBR) wiper malware.
About PreludePrelude hardens an organization's defenses by continuously “asking” it questions through the form of safe cyberattacks. These attacks respond immediately to the latest vulnerabilities and cyber events, turning complex technical descriptions into deployable “questions”.Our mission is to increase the reach, frequency and usage of advanced security for all organizations.