Elastic protects against data wiper malware targeting Ukraine: HERMETICWIPER
ID: 9ca21c4f-bf82-5e6d-90a6-75707b3a1de2
STIX ID: report--9ca21c4f-bf82-5e6d-90a6-75707b3a1de2
Feed Name: Elastic Security Labs
Threat Score
Elastic's report analyzes HERMETICWIPER, a Windows data-wiping campaign observed in February 2022 that targeted Ukrainian systems. The analysis covers the signed malicious binary and embedded EaseUS driver abuse, kernel-mode service interactions, raw-disk overwrite/shredding techniques (including NTFS tricks and boot-sector corruption), sample hashes and YARA detection, and available ECS/STIX artefacts and detections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
