logo

Newly identified wiper malware “PathWiper” targets critical infrastructure in Ukraine

ID: c7eb1cc6-2bbf-5a32-9aca-917d8fd444b4

STIX ID: report--c7eb1cc6-2bbf-5a32-9aca-917d8fd444b4

Feed Name: Cisco Talos

Threat Score
90/100

Date Published: 2025-06-05

Date Updated: 2026-04-27

Author: Jacob Finn

...
...

Cisco Talos reports a destructive attack against a Ukrainian critical infrastructure organization using a previously unidentified wiper called "PathWiper." The actor deployed the wiper via a legitimate endpoint administration console using a VBScript dropper (uacinstall.vbs) that wrote and executed sha256sum.exe; PathWiper programmatically enumerates and corrupts connected drives, NTFS artifacts (MBR, $MFT, $LogFile, etc.), and network shares. Talos attributes the operation to a Russia-nexus APT with high confidence, provides an IOC (SHA256), and recommends detection and prevention measures across endpoint, email, firewall, and network analytics products.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.