HermeticWizard
MITRE ATT&CK: S0698 View on attack.mitre.org
Aliases: HermeticWizard
- First seen
- 2022-02-23 00:00:00
- Malware type
- worm, wiper
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 14:21:40
Targeted industries: government-and-public-sector
Targeted regions: country_code:ua
Context
HermeticWizard is a worm that has been used to spread HermeticWiper in attacks against organizations in Ukraine since at least 2022.
Detection coverage
- 1 YARA rules
- 270 Sigma rules
Malware & tools used
- SMB/Windows Admin Shares (attack-pattern)
- Windows Command Shell (attack-pattern)
- Code Signing (attack-pattern)
- Service Execution (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Clear Windows Event Logs (attack-pattern)
- Password Guessing (attack-pattern)
- Native API (attack-pattern)
- Remote System Discovery (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- Network Service Discovery (attack-pattern)
- Lateral Tool Transfer (attack-pattern)
- Regsvr32 (attack-pattern)
- Component Object Model (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Rundll32 (attack-pattern)
Detection rules
- MALPEDIA_Win_Hermeticwizard_Auto (yara-rule)
Reports & references
- youtube.com — Watch (report)
- inquest.net — Ukraine Cyberwar Overview (report)
- Kaspersky — 106075 (report)
- ESET — Isaacwiper Hermeticwizard Wiper Worm Targeting Ukraine (report)
- brighttalk.com — 534324 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Hermeticwizard (report)
- twitter.com — 1501668345640366091 (report)
- twitter.com — 1502494650640351236 (report)
- MITRE ATT&CK — S0698 (report)