WhisperGate

MITRE ATT&CK: S0689 View on attack.mitre.org

Aliases: PAYWIPE, WhisperGate

Malware type
wiper, ransomware
Family
Malware family
Operating systems
windows
Related IoCs
1 (1 malicious)
Last IoC activity
2025-11-11 13:02:40
Profile updated
2026-07-07 12:44:03

Targeted industries: government-and-public-sector education-and-nonprofits technology-and-telecommunications

Targeted regions: country_code:ua

Context

WhisperGate is a multi-stage wiper designed to look like ransomware that has been used against multiple government, non-profit, and information technology organizations in Ukraine since at least January 2022.

Recent IoC activity

1 malicious indicator in Maltiverse are attributed to WhisperGate (S0689). The 1 most recently updated:

TypeIndicatorUpdatedSources
file sample 806129c7a1eb88ded49302df72bced64fe904c3dbcf043ef3f97138ca6e012b6 2025-11-11 1

Detection coverage

  • 6 YARA rules
  • 692 Sigma rules

Malware & tools used

  • Bootkit (attack-pattern)
  • Reflective Code Loading (attack-pattern)
  • Data Destruction (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • PowerShell (attack-pattern)
  • InstallUtil (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Native API (attack-pattern)
  • Web Protocols (attack-pattern)
  • File Deletion (attack-pattern)
  • Disk Structure Wipe (attack-pattern)
  • Disk Content Wipe (attack-pattern)
  • System Checks (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • Network Share Discovery (attack-pattern)
  • Service Execution (attack-pattern)
  • System Shutdown/Reboot (attack-pattern)
  • Process Hollowing (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Visual Basic (attack-pattern)
  • Create Process with Token (attack-pattern)
  • Web Service (attack-pattern)
  • Local Storage Discovery (attack-pattern)
  • Time Based Checks (attack-pattern)

Used by threat actors

Exploited vulnerabilities

  • CVE-2021-32648 (vulnerability)

Detection rules

  • CADOSECURITY_Whispergate_Stage_1 (yara-rule)
  • SIGNATURE_BASE_APT_HKTL_Wiper_Whispergate_Jan22_1 (yara-rule)
  • SIGNATURE_BASE_APT_HKTL_Wiper_Whispergate_Jan22_2 (yara-rule)
  • SIGNATURE_BASE_APT_HKTL_Wiper_Whispergate_Stage3_Jan22 (yara-rule)
  • SIGNATURE_BASE_MAL_OBFUSC_Unknown_Jan22_1 (yara-rule)
  • MALPEDIA_Win_Whispergate_Auto (yara-rule)

Reports & references

  • services.google.com — Google Fog Of War Research Report (report)
  • Microsoft — Cadet Blizzard Emerges As A Novel And Distinct Russian Threat Actor (report)
  • Microsoft — Destructive Malware Targeting Ukrainian Organizations (report)
  • Microsoft — Analysis Resources Cyber Threat Activity Ukraine (report)
  • Palo Alto Unit 42 — Ruinousursa (report)
  • trellix.com — Growling Bears Make Thunderous Noise (report)
  • CrowdStrike — Who Is Ember Bear (report)
  • Mandiant — Russia Invasion Ukraine Retaliation (report)
  • eclypsium.com — Conti Targets Critical Firmware (report)
  • Trend Micro — Ioc%20Resource%20For%20Russia Ukraine%20Conflict Related%20Cyberattacks 03032022 (report)
  • Trend Micro — Cyberattacks Are Prominent In The Russia Ukraine Conflict (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Whispergate (report)
  • cadosecurity.com — Resources For Dfir Professionals Responding To Whispergate Malware (report)
  • blogs.blackberry.com — Dot Net Stubs Sowing The Seeds Of Discord (report)
  • fortinet.com — The Increasing Wiper Malware Threat (report)
  • youtube.com — Watch (report)
  • inquest.net — Ukraine Cyberwar Overview (report)
  • tesorion.nl — Report Osint Russia Ukraine Conflict Cyberaspect (report)
  • mandiant.widen.net — M Trends 2023 (report)
  • cyberpeaceinstitute.org — Ukraine Timeline Of Cyberattacks (report)
  • inquest.net — 380 Glowspark (report)
  • CrowdStrike — The Anatomy Of Wiper Malware Part 1 (report)
  • Microsoft — Re4Vwwd (report)
  • CrowdStrike — The Anatomy Of Wiper Malware Part 3 (report)
  • Microsoft — A Year Of Russian Hybrid Warfare In Ukraine Ms Threat Intelligence 1 (report)

External references