New Destructive Malware Used In Ukraine Cyber Attacks.
The UK NCSC has cautioned over a new wiper malware being used in the war in Ukraine known as “Hermetic wiper!. Often malware such as this starts in a targeted fashion, but is designed to spread and cannot always be controlled once released, ending up in countries around the world.
NCSC advises organisations to act following Russia’s… – NCSC.GOV.UK
EDR protection of endpoints and offline backup of data can help mitigate this threat.
Key points:
- On February 23rd, the threat intelligence community began observing a new wiper malware sample circulating in Ukrainian organizations.
- Our analysis shows a signed driver is being used to deploy a wiper that targets Windows devices, manipulating the MBR resulting in subsequent boot failure.
- This blog includes the technical details of the wiper, dubbed HermeticWiper, and includes IOCs to allow organizations to stay protected from this attack.
- This sample is actively being used against Ukrainian organizations, and this blog will be updated as more information becomes available.
- We also analyse a ‘ransomware’, called PartyTicket, reportedly used as a decoy during wiping operations.
Using NORSOC and SentinelOne this threat can be detected and mitigated.
Links
CISA Alert
Destructive Malware Targeting Organizations in Ukraine | CISA
NCSC heightened threat guidance
Actions to take when the cyber threat is heightened – NCSC.GOV.UK
Technical Analysis and IOCs
HermeticWiper | New Destructive Malware Used In Cyber Attacks on Ukraine – SentinelOne
Book A Chat
If you want to discuss your cyber security more or ask us any questions please do book a free no obligation chat with us.