惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

人人都是产品经理
人人都是产品经理
宝玉的分享
宝玉的分享
小众软件
小众软件
有赞技术团队
有赞技术团队
月光博客
月光博客
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
MyScale Blog
MyScale Blog
Engineering at Meta
Engineering at Meta
Stack Overflow Blog
Stack Overflow Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
N
Netflix TechBlog - Medium
D
Docker
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
MongoDB | Blog
MongoDB | Blog
WordPress大学
WordPress大学
J
Java Code Geeks
罗磊的独立博客
V
Visual Studio Blog
雷峰网
雷峰网
H
Help Net Security
T
The Blog of Author Tim Ferriss
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
大猫的无限游戏
大猫的无限游戏
F
Fortinet All Blogs

Intel 471 Blog

TeamPCP Supply Chain Attacks Turning Geopolitical Tension into Actionable Intelligence CVE-2025-68613: Zerobot botnet exploits critical vulnerability impacting n8n AI orchestration platform Introducing Cyber Threat Exposure Bundle: A Unified Approach to External Risk CVE-2026-20127: Critical Cisco SD-WAN vulnerability exploited in wild Handala Threat Group OpenClaw: A viral AI assistant and a magnet for infostealer malware and ClickFix trickery Israeli, US strikes against Iran triggers a surge in hacktivist activity CVE-2026-1731: Finding a critical RCE in an age of AI-driven vulnerability research Born to bypass MFA: Taking down Tycoon 2FA The UK Cyber Security Resilience Bill How AI and the human advantage beat tomorrow’s threats Winter Olympics 2026: Hacktivism Surges Ahead of Protests and Suspected Sabotage How Threat Hunting and “Good” Metrics Help The Business Likely fake ransomware operator 0APT causes panic — Our analysis Hunting APTs: from state policy to TTPs CrazyHunter Ransomware DevMan Ransomware Introducing HUNTER Tuning: a New Tool for Driving Behavioral Threat Hunt Detections Battling check fraud in the U.S. Gootloader Malware Update Shai-Hulud Worm 2.0 New FvncBot Android banking trojan targets Poland White Paper Preview: Black "Fraud Day” and Beyond — The Key Cyber Threats Facing the Retail Sector this Holiday Season Threat hunting case study: Detecting IAB activity Using deception to extract cyber threat intelligence Lynx Ransomware Qilin Ransomware Group ClickFix: Tricking users into installing infostealers Cybercrime Takedowns: Trust, Partnerships and Focus
HermeticWiper Malware
Intel 471 · 2022-02-25 · via Intel 471 Blog

OVERVIEW

The HermeticWiper malware variant was first identified by researchers from ESET and Broadcom’s Symantec on February 23, 2022 and has been observed attacking Ukrainian government and organizations during the tensions between Ukraine and Russia. The variant has been observed as a wiper, similar in purpose to the NotPetya attack in 2017 and the more recent WhisperGate wiper variant of January 2022, which is to destroy data and render it unrecoverable.

TARGETING

HermeticWiper, as of February 2022, has been observed being used in an active campaign targeting Ukrainian government and related organizations.

DELIVERY

Hermetic's method of delivery has not been confirmed as of January 2022, but speculation says it can be delivered as email attachments, malicious links, and social engineering. It was reported that one of the targeted organizations had the wiper dropped via GPO, meaning it already had initial access.

INSTALLATION

HeremeticWiper has been observed being installed by a malicious code-signed application, allowing it to circumvent initial security tooling. Then abuses legitimate drivers from EaseUS partition master software to execute the data corruption system wide.

PERSISTENCE

Persistence is achieved through the observed corruption of the Master Boot Record on all physical drives associated, rendering the victim host unrecoverable.

Get the Free Hunt Packages!

Check Out Other Emerging Threats >

Threat Update - 3 March 2022

Two additional hunt packages have been released pertaining to HermeticWiper.
One package focuses on the registry detection for the service creation behavior
associated with HermeticWiper. This allows for more logs to be utilized for
identification. The other package focuses on the deployment technique used by
HermeticWizard to bypass application whitelisting, which is common with
circumventing AppLocker in order to deploy HermeticWiper in a victim's
environment

Threat Update - 24 Feb 2022

Threat Summary

The HermeticWiper malware variant was first identified by researchers from ESET and Broadcom’s Symantec on February 23, 2022 and has been observed attacking Ukrainian government and organizations during the tensions between Ukraine and Russia. The malware's emergence comes after DDOS (Distributed denial of service) attacks against Ukrainian websites right before discovery. The name "Hermetic" is derived from the name of the Cypriot company that the certificate was issued to "Hermetica Digital". As for specific intent and targets, these have not been identified explicitly as of yet but due to the events occurring in parallel, systems within or associated to Ukraine should be prepared accordingly - with hundreds of computers on their networks being already targeted since its discovery.

The variant has been observed as a wiper, similar in purpose to the NotPetya attack in 2017 and the more recent WhisperGate wiper variant of January 2022, which is to destroy data and render it unrecoverable. The difference that is seen in HermeticWiper (in addition to the utilization of a code signed certificate) is the abuse of legitimate drivers for data corruption. Although currently targeting Ukraine and due to the "freshness" of this variant upon writing, the potentiality of this malware or a modified version of it or its techniques being utilized by another threat group is feasible.

Threat Synopsis

The HermeticWiper malware variant was discovered targeting Ukraine government and organizations affiliated in late Febuary 2022 during the ongoing Ukraine-Russia conflict, with observed intentions to cause irreparable data loss to targeted victims via data corruption. The initial distribution of HermeticWiper could be via common vectors, such as email attachments, malicious links, and social engineering - however it was reported that one of the targeted organizations had the wiper dropped via GPO, meaning that they were already compromised before the use of HermeticWiper.

In order to avoid detection from security tools, the variant is signed by a digital certificate (under the company Hermetica Digital Ltd) and is a small application that comes in at around 114KBs in size. After execution, it abuses legitimate drivers from EaseUS partition master software in order to conduct the system wide data corruption. The data corruption combs the system and includes Windows Shadow Copies as well.

In continuation of the process, the malware enumerates Physical Drives and corrupts the Master Boot Record for every physical drive - SentinelOne states the variant operates differently depending on the type of partitions as well (FAT vs NTFS), choosing to parse the Master File Table initially for NTFS. It has been observed that the malware also enumerates common folders, registry and logs, as well as disabling crash dumps. It is at this point that the victim's machine is restarted and rendered unusable after the wiper has run its course.

Get the Free Hunt Packages!

Check Out Other Emerging Threats >