logo

HermeticWiper & resurgence of targeted attacks on Ukraine

ID: b5fd6567-6981-51de-b570-4c8fceaa1bdb

STIX ID: report--b5fd6567-6981-51de-b570-4c8fceaa1bdb

Feed Name: Zscaler Security Research Blog

Threat Score
90/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

ThreatLabz provides a technical analysis of HermeticWiper and two related targeted spearphishing campaigns against Ukrainian entities (Nov 2020–Feb 2022). The report details delivery chains (malicious documents, macros, VBScript, LNK→MSI→NSIS), destructive wiper behavior (kernel driver usage to overwrite MBR and MFT, disable VSS and crash dumps), embedded signed drivers, C2/infrastructure overlap with Gamaredon, and extensive IOCs (hashes, domains, IPs) for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.