HermeticWiper
MITRE ATT&CK: S0697 View on attack.mitre.org
Aliases: Trojan.Killdisk, DriveSlayer, FoxBlade, KillDisk.NCV, NEARMISS, HermeticWiper
- First seen
- 2022-02-23 00:00:00
- Malware type
- wiper
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 13 (13 malicious)
- Last IoC activity
- 2026-08-27 16:04:53
- Profile updated
- 2026-07-07 12:44:09
Targeted industries: government-and-public-sector financial-services defense-and-aerospace transportation-and-logistics technology-and-telecommunications
Targeted regions: country_code:ua country_code:lv country_code:lt
Context
HermeticWiper is a data wiper that has been used since at least early 2022, primarily against Ukraine with additional activity observed in Latvia and Lithuania. Some sectors targeted include government, financial, defense, aviation, and IT services.
Recent IoC activity
13 malicious indicators in Maltiverse are attributed to HermeticWiper (S0697). The 13 most recently updated:
Detection coverage
- 4 YARA rules
- 579 Sigma rules
Malware & tools used
- Scheduled Task (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- Access Token Manipulation (attack-pattern)
- Group Policy Modification (attack-pattern)
- Data Destruction (attack-pattern)
- Code Signing (attack-pattern)
- Modify Registry (attack-pattern)
- Indicator Removal (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Disk Structure Wipe (attack-pattern)
- Inhibit System Recovery (attack-pattern)
- Time Based Checks (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Windows Command Shell (attack-pattern)
- System Information Discovery (attack-pattern)
- Native API (attack-pattern)
- Compression (attack-pattern)
- Local Storage Discovery (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Clear Windows Event Logs (attack-pattern)
- Windows Service (attack-pattern)
- File Deletion (attack-pattern)
- Service Stop (attack-pattern)
- Disk Content Wipe (attack-pattern)
- Service Execution (attack-pattern)
Detection rules
- TRELLIX_ARC_Hermeticwiper (yara-rule)
- CLUSTER25_UNC1222_Hermeticwiper_23433_10001 (yara-rule)
- SEKOIA_Wiper_Hermeticwiper_Variants (yara-rule)
- MALPEDIA_Win_Hermeticwiper_Auto (yara-rule)
Reports & references
- services.google.com — Google Fog Of War Research Report (report)
- services.google.com — Apt44 Unearthing Sandworm (report)
- Microsoft — Analysis Resources Cyber Threat Activity Ukraine (report)
- trellix.com — Growling Bears Make Thunderous Noise (report)
- Mandiant — Russia Invasion Ukraine Retaliation (report)
- eclypsium.com — Conti Targets Critical Firmware (report)
- Trend Micro — Ioc%20Resource%20For%20Russia Ukraine%20Conflict Related%20Cyberattacks 03032022 (report)
- cybersecurity.att.com — Analysis On Recent Wiper Attacks Examples And How They Wiper Malware Works (report)
- trustwave.com — Overview Of The Cyber Weapons Used In The Ukraine Russia War (report)
- fortinet.com — The Increasing Wiper Malware Threat (report)
- youtube.com — Watch (report)
- inquest.net — Ukraine Cyberwar Overview (report)
- socradar.io — What You Need To Know About Russian Cyber Escalation In Ukraine (report)
- tesorion.nl — Report Osint Russia Ukraine Conflict Cyberaspect (report)
- mandiant.widen.net — M Trends 2023 (report)
- cyberpeaceinstitute.org — Ukraine Timeline Of Cyberattacks (report)
- cip.gov.ua — Khto Stoyit Za Kiberatakami Na Ukrayinsku Kritichnu Informaciinu Infrastrukturu Statistika 15 22 Bereznya (report)
- twitter.com — 1496878431719473155 (report)
- CrowdStrike — The Anatomy Of Wiper Malware Part 1 (report)
- Microsoft — Re4Vwwd (report)
- CrowdStrike — The Anatomy Of Wiper Malware Part 3 (report)
- Microsoft — Preparing Russian Cyber Offensive Ukraine (report)
- Microsoft — A Year Of Russian Hybrid Warfare In Ukraine Ms Threat Intelligence 1 (report)
- nextgov.com — 363558 (report)
- blog.nviso.eu — Threat Update Ukraine Russia Tensions (report)
External references
- mitre-attack — S0697
- Trojan.Killdisk
- DriveSlayer
- CISA AA22-057A Destructive Malware February 2022
- Crowdstrike PartyTicket March 2022
- Qualys Hermetic Wiper March 2022
- ESET Hermetic Wiper February 2022
- SentinelOne Hermetic Wiper February 2022
- Symantec Ukraine Wipers February 2022
- Crowdstrike DriveSlayer February 2022
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy