logo

Uniquely Destructive PathWiper Payload Emerges in Ukraine Attacks

ID: 6712cd34-4d7b-552a-b192-adf4d17d774d

STIX ID: report--6712cd34-4d7b-552a-b192-adf4d17d774d

Feed Name: Halcyon Blog

Threat Score
85/100

Date Published: 2025-06-06

Date Updated: 2026-04-28

...
...

Researchers uncovered PathWiper, a new wiper deployed in an attack on an unnamed Ukrainian organization and attributed to a Russia-linked APT; the malware programmatically enumerates connected and network shares and overwrites storage with random data to prevent recovery, was deployed via a legitimate endpoint administration framework, and is being framed as part of a broader pattern of destructive attacks against Ukrainian critical infrastructure with a high risk of tactics being adopted by criminal ransomware groups.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.