logo

Technical Analysis of The Hermetic Wiper Malware Used to Target Ukraine

ID: 0c34d69f-4621-5732-a8bc-77346cdb983f

STIX ID: report--0c34d69f-4621-5732-a8bc-77346cdb983f

Feed Name: CloudSEK Blog

Threat Score
90/100

Date Published: 2022-03-02

Date Updated: 2026-04-27

...
...

ESET researchers identified and analyzed Hermetic Wiper, a destructive Windows wiper observed on 23 February 2022 that abuses signed binaries and a dropped signed driver to gain privileged raw-disk access, disable forensic mechanisms (crash dumps, VSS), and corrupt boot and filesystem metadata (MBR, NTFS/FAT structures), rendering systems unusable; the report includes technical TTPs, service/driver installation and cleanup behavior, and file/hash indicators for detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.