0333 032 8979 info@norsoc.com

New Destructive Malware Used In Ukraine Cyber Attacks.

 

The UK NCSC has cautioned over a new wiper malware being used in the war in Ukraine known as “Hermetic wiper!. Often malware such as this starts in a targeted fashion, but is designed to spread and cannot always be controlled once released, ending up in countries around the world.

NCSC advises organisations to act following Russia’s… – NCSC.GOV.UK

EDR protection of endpoints and offline backup of data can help mitigate this threat.

Key points:

  1. On February 23rd, the threat intelligence community began observing a new wiper malware sample circulating in Ukrainian organizations.
  2. Our analysis shows a signed driver is being used to deploy a wiper that targets Windows devices, manipulating the MBR resulting in subsequent boot failure.
  3. This blog includes the technical details of the wiper, dubbed HermeticWiper, and includes IOCs to allow organizations to stay protected from this attack.
  4. This sample is actively being used against Ukrainian organizations, and this blog will be updated as more information becomes available.
  5. We also analyse a ‘ransomware’, called PartyTicket, reportedly used as a decoy during wiping operations.

Using NORSOC and SentinelOne this threat can be detected and mitigated.

 

Links 

CISA Alert

Destructive Malware Targeting Organizations in Ukraine | CISA

NCSC heightened threat guidance

Actions to take when the cyber threat is heightened – NCSC.GOV.UK

Technical Analysis and IOCs

HermeticWiper | New Destructive Malware Used In Cyber Attacks on Ukraine – SentinelOne

Book A Chat

If you want to discuss your cyber security more or ask us any questions please do book a free no obligation chat with us.