ArguePatch

Malware type
loader, wiper
Profile updated
2026-07-07 13:09:00

Targeted industries: energy-and-utilities

Targeted regions: country_code:ua

Context

During a campaign against a Ukrainian energy provider, a new loader of a new version of CaddyWiper called "ArguePatch" was observed by ESET researchers. ArguePatch is a modified version of Hex-Ray's Remote Debugger Server (win32_remote.exe). ArguePatch expects a decryption key and the file of the CaddyWiper shellcode as command line parameters.

Reports & references

  • Mandiant — Gru Rise Telegram Minions (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Arguepatch (report)
  • ESET — Industroyer2 Industroyer Reloaded (report)

External references