ArguePatch
- Malware type
- loader, wiper
- Profile updated
- 2026-07-07 13:09:00
Targeted industries: energy-and-utilities
Targeted regions: country_code:ua
Context
During a campaign against a Ukrainian energy provider, a new loader of a new version of CaddyWiper called "ArguePatch" was observed by ESET researchers. ArguePatch is a modified version of Hex-Ray's Remote Debugger Server (win32_remote.exe). ArguePatch expects a decryption key and the file of the CaddyWiper shellcode as command line parameters.
Reports & references
- Mandiant — Gru Rise Telegram Minions (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Arguepatch (report)
- ESET — Industroyer2 Industroyer Reloaded (report)