Fresh strain of pro-Russian wiper flushes Ukrainian critical infrastructure
ID: 99a0581c-ceb3-516e-8ada-125552713780
STIX ID: report--99a0581c-ceb3-516e-8ada-125552713780
Feed Name: The Register (Security)
Cisco Talos researchers identified a new destructive wiper called PathWiper used against an unspecified Ukrainian critical infrastructure organization and attributed it to a Russia‑nexus APT with similarities to HermeticWiper/Sandworm. PathWiper programmatically enumerates and dismounts drives, reads NTFS metadata and overwrites files, volumes and master boot records with randomized data, and could cause widespread destruction if deployed across an organization's network given the attackers' control of endpoint administration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
