Inhibit System Recovery, Technique T1490 - Enterprise (original) (raw)
During the 2025 Poland Wiper Attacks, the adversaries deleted Windows Volume Shadow Copies using vssadmin delete shadows.[10]
Akira will delete system volume shadow copies via PowerShell commands.[11][12]
Avaddon deletes backups and shadow copies using native system tools.[13][14]
Babuk has the ability to delete shadow volumes using vssadmin.exe delete shadows /all /quiet.[15][16]
BFG Agonizer wipes the boot sector of infected machines to inhibit system recovery.[17]
BitPaymer attempts to remove the backup shadow files from the host using vssadmin.exe Delete Shadows /All /Quiet.[18]
Black Basta can delete shadow copies using vssadmin.exe.[19][20][21][22][23][24][25][26][26][27]
BlackByte resized and deleted volume shadow copy files to prevent system recovery after encryption.[28][29]
BlackByte 2.0 Ransomware modifies volume shadow copies during execution in a way that destroys them on the victim machine.[30]
BlackByte Ransomware deletes all volume shadow copies and restore points among other actions to inhibit system recovery following ransomware deployment.[31]
BlackCat can delete shadow copies using vssadmin.exe delete shadows /all /quiet and wmic.exe Shadowcopy Delete; it can also modify the boot loader using bcdedit /set {default} recoveryenabled No.[32]
Clop can delete the shadow volumes with vssadmin Delete Shadows /all /quiet and can use bcdedit to disable recovery options.[33]
Conficker resets system restore points and deletes backup files.[34]
Conti can delete Windows Volume Shadow Copies using vssadmin.[35]
DarkGate can delete system restore points through the command cmd.exe /c vssadmin delete shadows /for=c: /all /quiet".[36]
DarkWatchman can delete shadow volumes using vssadmin.exe.[37]
DEATHRANSOM can delete volume shadow copies on compromised hosts.[38]
Diavol can delete shadow copies using the IVssBackupComponents COM object to call the DeleteSnapshots method.[39]
EKANS removes backups of Volume Shadow Copies to disable any restoration capabilities.[40][41]
Embargo has cleared files from the recycle bin by invoking SHEmptyRecycleBinW() and disabled Windows recovery through C:\Windows\System32\cmd.exe /q /c bcdedit /set {default} recoveryenabled no.[42]
FIVEHANDS has the ability to delete volume shadow copies on compromised hosts.[38][43]
H1N1 disable recovery options and deletes shadow copies from the victim.[44]
HELLOKITTY can delete volume shadow copies on compromised hosts.[38]
HermeticWiper can disable the VSS service on a compromised host using the service control manager.[45][46][47]
INC Ransomware can delete volume shadow copy backups from victim machines.[48]
InvisiMole can can remove all system restore points.[49]
JCry has been observed deleting shadow copies to ensure that data cannot be restored easily.[50]
LockBit 2.0 has the ability to delete volume shadow copies on targeted hosts.[51][52]
LockBit 3.0 can delete volume shadow copies.[53][54][55]
Maze has attempted to delete the shadow volumes of infected machines, once before and once after the encryption process.[56][57]
Medusa Group has deleted recovery files such as shadow copies using vssadmin.exe.[58][59][60][61]
Medusa Ransomware has deleted recovery files such as shadow copies using vssadmin.exe.[58][59][60][61]
MegaCortex has deleted volume shadow copies using vssadmin.exe.[62]
Meteor can use bcdedit to delete different boot identifiers on a compromised host; it can also use vssadmin.exe delete shadows /all /quiet and C:\\Windows\\system32\\wbem\\wmic.exe shadowcopy delete.[63]
MultiLayer Wiper wipes the boot sector of infected systems to inhibit system recovery.[17]
Netwalker can delete the infected system's Shadow Volumes to prevent recovery.[64][65]
Olympic Destroyer uses the native Windows utilities vssadmin, wbadmin, and bcdedit to delete and disable operating system recovery features such as the Windows backup catalog and Windows Automatic Repair.[1]
Playcrypt can use AlphaVSS to delete shadow copies.[66]
Prestige can delete the backup catalog from the target system using: c:\Windows\System32\wbadmin.exe delete catalog -quiet and can also delete volume shadow copies using: \Windows\System32\vssadmin.exe delete shadows /all /quiet.[67]
ProLock can use vssadmin.exe to remove volume shadow copies.[68]
Pysa has the functionality to delete shadow copies.[69]
Qilin can execute vssadmin.exe delete shadows /all /quiet to remove volume shadow copies and can disable High Availability (HA) and Distributed Resource Scheduler (DRS) in vCenter clusters.[70][71][72][73]
Ragnar Locker can delete volume shadow copies using vssadmin delete shadows /all /quiet.[74]
RansomHub has used vssadmin.exe to delete volume shadow copies.[75][76]
REvil can use vssadmin to delete volume shadow copies and bcdedit to disable recovery features.[77][78][79][80][81][82][83][84][85]
ROADSWEEP has the ability to disable SystemRestore and Volume Shadow Copies.[86][87]
RobbinHood deletes shadow copies to ensure that all the data cannot be restored easily.[88]
Royal can delete shadow copy backups with vssadmin.exe using the command delete shadows /all /quiet.[89][90][91]
Ryuk has used vssadmin Delete Shadows /all /quiet to to delete volume shadow copies and vssadmin resize shadowstorage to force deletion of shadow copies created by third-party applications.[92]
Sandworm Team uses Prestige to delete the backup catalog from the target system using: C:\Windows\System32\wbadmin.exe delete catalog -quiet and to delete volume shadow copies using: C:\Windows\System32\vssadmin.exe delete shadows /all /quiet. [67]
Scattered Spider has stopped the Volume Shadow Copy service on compromised hosts.[93]
Storm-0501 has deleted snapshots, restore points, storage accounts, and backup services to prevent remediation and restoration.[94] Storm-0501 has also impacted Azure resources through the targeting of Microsoft.Compute/snapshots/delete,Microsoft.Compute/restorePointCollections/delete,Microsoft.Storage/storageAccounts/delete, andMicrosoft.RecoveryServices/Vaults/backupFabrics/protectionContainers/delete.[94]
VOID MANTICORE has deleted virtual machines directly from the virtualization platform.[95]
WannaCry uses vssadmin, wbadmin, bcdedit, and wmic to delete and disable operating system recovery features.[96][2][97]
WastedLocker can delete shadow volumes.[98][99][100]
Wizard Spider has used WMIC and vssadmin to manually delete volume shadow copies. Wizard Spider has also used Conti ransomware to delete volume shadow copies automatically with the use of vssadmin.[101]