logo

Fresh strain of pro-Russian wiper flushes Ukrainian critical infrastructure

ID: 99a0581c-ceb3-516e-8ada-125552713780

STIX ID: report--99a0581c-ceb3-516e-8ada-125552713780

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2025-06-06

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Cisco Talos researchers identified a new destructive wiper called PathWiper used against an unspecified Ukrainian critical infrastructure organization and attributed it to a Russia‑nexus APT with similarities to HermeticWiper/Sandworm. PathWiper programmatically enumerates and dismounts drives, reads NTFS metadata and overwrites files, volumes and master boot records with randomized data, and could cause widespread destruction if deployed across an organization's network given the attackers' control of endpoint administration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.