DesertBlade

First seen
2022-03-01 00:00:00
Malware type
wiper
Profile updated
2026-07-07 13:01:31

Targeted industries: government-and-public-sector

Targeted regions: country_code:ua

Context

According to Microsoft, this was used in a limited destructive malware attack in early March 2022 impacting a single Ukrainian entity. DesertBlade is responsible for iteratively overwriting and then deleting overwritten files on all accessible drives (sparing the system if it is a domain controller).

Reports & references

  • Microsoft — Analysis Resources Cyber Threat Activity Ukraine (report)
  • youtube.com — Watch (report)
  • Microsoft — A Year Of Russian Hybrid Warfare In Ukraine Ms Threat Intelligence 1 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Desertblade (report)

External references