HermeticWiper
ID: 64bf6f9b-06d0-5c5b-97a6-d3af3063cf45
STIX ID: report--64bf6f9b-06d0-5c5b-97a6-d3af3063cf45
Feed Name: Arctic Wolf Blog
Threat Score
HermeticWiper is a destructive wiper first identified on February 23, 2022, targeting Ukrainian organizations across aviation, defense, financial, and IT sectors (with at least one infection observed in Lithuania); the malware escalates privileges, disables crash dumps and Volume Shadow Service, overwrites the first 512 bytes of drives (MBR) to prevent booting, and was observed alongside a Golang-based ransomware and DDoS activity prior to Russia’s assault on Ukraine.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
