HermeticWizard

MITRE ATT&CK: S0698 View on attack.mitre.org

Aliases: HermeticWizard

First seen
2022-02-23 00:00:00
Malware type
worm, wiper
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 14:21:40

Targeted industries: government-and-public-sector

Targeted regions: country_code:ua

Context

HermeticWizard is a worm that has been used to spread HermeticWiper in attacks against organizations in Ukraine since at least 2022.

Detection coverage

  • 1 YARA rules
  • 270 Sigma rules

Malware & tools used

  • SMB/Windows Admin Shares (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Code Signing (attack-pattern)
  • Service Execution (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Clear Windows Event Logs (attack-pattern)
  • Password Guessing (attack-pattern)
  • Native API (attack-pattern)
  • Remote System Discovery (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • Network Service Discovery (attack-pattern)
  • Lateral Tool Transfer (attack-pattern)
  • Regsvr32 (attack-pattern)
  • Component Object Model (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Rundll32 (attack-pattern)

Detection rules

  • MALPEDIA_Win_Hermeticwizard_Auto (yara-rule)

Reports & references

  • youtube.com — Watch (report)
  • inquest.net — Ukraine Cyberwar Overview (report)
  • Kaspersky — 106075 (report)
  • ESET — Isaacwiper Hermeticwizard Wiper Worm Targeting Ukraine (report)
  • brighttalk.com — 534324 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Hermeticwizard (report)
  • twitter.com — 1501668345640366091 (report)
  • twitter.com — 1502494650640351236 (report)
  • MITRE ATT&CK — S0698 (report)

External references