logo

A Technical Analysis of ISAACWiper

ID: 7dee9aab-d3f5-5caf-adcb-b697b0ed59fb

STIX ID: report--7dee9aab-d3f5-5caf-adcb-b697b0ed59fb

Feed Name: WatchGuard Secplicity Blog

Threat Score
90/100

Date Published: 2023-02-11

Date Updated: 2026-05-01

Author: The Editor

...
...

### Executive summary: This report provides a detailed reverse-engineering analysis of ISAACWiper, a 32-bit Windows DLL wiper discovered on Ukrainian networks immediately prior to the 24 February 2022 invasion and attributed to Russia’s GRU (Sandworm). The analysis covers file metadata and hashes, imported APIs, exported entrypoints, use of GetTickCount-seeded Mersenne Twister PRNG to generate overwrite data, techniques to lock volumes and destroy the MBR by writing the first 10,000 bytes of physical drives, iterative file/directory overwrites, logging behavior, and observable indicators that caused systems to fail and force reboots.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.