Newly identified wiper malware “PathWiper” targets critical infrastructure in Ukraine
ID: c7eb1cc6-2bbf-5a32-9aca-917d8fd444b4
STIX ID: report--c7eb1cc6-2bbf-5a32-9aca-917d8fd444b4
Feed Name: Cisco Talos
Cisco Talos reports a destructive attack against a Ukrainian critical infrastructure organization using a previously unidentified wiper called "PathWiper." The actor deployed the wiper via a legitimate endpoint administration console using a VBScript dropper (uacinstall.vbs) that wrote and executed sha256sum.exe; PathWiper programmatically enumerates and corrupts connected drives, NTFS artifacts (MBR, $MFT, $LogFile, etc.), and network shares. Talos attributes the operation to a Russia-nexus APT with high confidence, provides an IOC (SHA256), and recommends detection and prevention measures across endpoint, email, firewall, and network analytics products.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
