惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

WordPress大学
WordPress大学
T
The Blog of Author Tim Ferriss
F
Fortinet All Blogs
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
阮一峰的网络日志
阮一峰的网络日志
The GitHub Blog
The GitHub Blog
Y
Y Combinator Blog
MyScale Blog
MyScale Blog
雷峰网
雷峰网
博客园 - 叶小钗
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
GbyAI
GbyAI
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
博客园 - 三生石上(FineUI控件)
云风的 BLOG
云风的 BLOG
V
V2EX
宝玉的分享
宝玉的分享
酷 壳 – CoolShell
酷 壳 – CoolShell
N
Netflix TechBlog - Medium
Vercel News
Vercel News
美团技术团队
人人都是产品经理
人人都是产品经理
The Cloudflare Blog

Intel 471 Blog

TeamPCP Supply Chain Attacks Turning Geopolitical Tension into Actionable Intelligence CVE-2025-68613: Zerobot botnet exploits critical vulnerability impacting n8n AI orchestration platform Introducing Cyber Threat Exposure Bundle: A Unified Approach to External Risk CVE-2026-20127: Critical Cisco SD-WAN vulnerability exploited in wild Handala Threat Group OpenClaw: A viral AI assistant and a magnet for infostealer malware and ClickFix trickery Israeli, US strikes against Iran triggers a surge in hacktivist activity CVE-2026-1731: Finding a critical RCE in an age of AI-driven vulnerability research Born to bypass MFA: Taking down Tycoon 2FA The UK Cyber Security Resilience Bill How AI and the human advantage beat tomorrow’s threats Winter Olympics 2026: Hacktivism Surges Ahead of Protests and Suspected Sabotage How Threat Hunting and “Good” Metrics Help The Business Likely fake ransomware operator 0APT causes panic — Our analysis Hunting APTs: from state policy to TTPs CrazyHunter Ransomware DevMan Ransomware Introducing HUNTER Tuning: a New Tool for Driving Behavioral Threat Hunt Detections Battling check fraud in the U.S. Gootloader Malware Update Shai-Hulud Worm 2.0 New FvncBot Android banking trojan targets Poland White Paper Preview: Black "Fraud Day” and Beyond — The Key Cyber Threats Facing the Retail Sector this Holiday Season Threat hunting case study: Detecting IAB activity Using deception to extract cyber threat intelligence Lynx Ransomware Qilin Ransomware Group ClickFix: Tricking users into installing infostealers Cybercrime Takedowns: Trust, Partnerships and Focus
HermeticWiper Malware
Intel 471 · 2022-02-25 · via Intel 471 Blog

OVERVIEW

The HermeticWiper malware variant was first identified by researchers from ESET and Broadcom’s Symantec on February 23, 2022 and has been observed attacking Ukrainian government and organizations during the tensions between Ukraine and Russia. The variant has been observed as a wiper, similar in purpose to the NotPetya attack in 2017 and the more recent WhisperGate wiper variant of January 2022, which is to destroy data and render it unrecoverable.

TARGETING

HermeticWiper, as of February 2022, has been observed being used in an active campaign targeting Ukrainian government and related organizations.

DELIVERY

Hermetic's method of delivery has not been confirmed as of January 2022, but speculation says it can be delivered as email attachments, malicious links, and social engineering. It was reported that one of the targeted organizations had the wiper dropped via GPO, meaning it already had initial access.

INSTALLATION

HeremeticWiper has been observed being installed by a malicious code-signed application, allowing it to circumvent initial security tooling. Then abuses legitimate drivers from EaseUS partition master software to execute the data corruption system wide.

PERSISTENCE

Persistence is achieved through the observed corruption of the Master Boot Record on all physical drives associated, rendering the victim host unrecoverable.

Get the Free Hunt Packages!

Check Out Other Emerging Threats >

Threat Update - 3 March 2022

Two additional hunt packages have been released pertaining to HermeticWiper.
One package focuses on the registry detection for the service creation behavior
associated with HermeticWiper. This allows for more logs to be utilized for
identification. The other package focuses on the deployment technique used by
HermeticWizard to bypass application whitelisting, which is common with
circumventing AppLocker in order to deploy HermeticWiper in a victim's
environment

Threat Update - 24 Feb 2022

Threat Summary

The HermeticWiper malware variant was first identified by researchers from ESET and Broadcom’s Symantec on February 23, 2022 and has been observed attacking Ukrainian government and organizations during the tensions between Ukraine and Russia. The malware's emergence comes after DDOS (Distributed denial of service) attacks against Ukrainian websites right before discovery. The name "Hermetic" is derived from the name of the Cypriot company that the certificate was issued to "Hermetica Digital". As for specific intent and targets, these have not been identified explicitly as of yet but due to the events occurring in parallel, systems within or associated to Ukraine should be prepared accordingly - with hundreds of computers on their networks being already targeted since its discovery.

The variant has been observed as a wiper, similar in purpose to the NotPetya attack in 2017 and the more recent WhisperGate wiper variant of January 2022, which is to destroy data and render it unrecoverable. The difference that is seen in HermeticWiper (in addition to the utilization of a code signed certificate) is the abuse of legitimate drivers for data corruption. Although currently targeting Ukraine and due to the "freshness" of this variant upon writing, the potentiality of this malware or a modified version of it or its techniques being utilized by another threat group is feasible.

Threat Synopsis

The HermeticWiper malware variant was discovered targeting Ukraine government and organizations affiliated in late Febuary 2022 during the ongoing Ukraine-Russia conflict, with observed intentions to cause irreparable data loss to targeted victims via data corruption. The initial distribution of HermeticWiper could be via common vectors, such as email attachments, malicious links, and social engineering - however it was reported that one of the targeted organizations had the wiper dropped via GPO, meaning that they were already compromised before the use of HermeticWiper.

In order to avoid detection from security tools, the variant is signed by a digital certificate (under the company Hermetica Digital Ltd) and is a small application that comes in at around 114KBs in size. After execution, it abuses legitimate drivers from EaseUS partition master software in order to conduct the system wide data corruption. The data corruption combs the system and includes Windows Shadow Copies as well.

In continuation of the process, the malware enumerates Physical Drives and corrupts the Master Boot Record for every physical drive - SentinelOne states the variant operates differently depending on the type of partitions as well (FAT vs NTFS), choosing to parse the Master File Table initially for NTFS. It has been observed that the malware also enumerates common folders, registry and logs, as well as disabling crash dumps. It is at this point that the victim's machine is restarted and rendered unusable after the wiper has run its course.

Get the Free Hunt Packages!

Check Out Other Emerging Threats >