DesertBlade
- First seen
- 2022-03-01 00:00:00
- Malware type
- wiper
- Profile updated
- 2026-07-07 13:01:31
Targeted industries: government-and-public-sector
Targeted regions: country_code:ua
Context
According to Microsoft, this was used in a limited destructive malware attack in early March 2022 impacting a single Ukrainian entity. DesertBlade is responsible for iteratively overwriting and then deleting overwritten files on all accessible drives (sparing the system if it is a domain controller).
Reports & references
- Microsoft — Analysis Resources Cyber Threat Activity Ukraine (report)
- youtube.com — Watch (report)
- Microsoft — A Year Of Russian Hybrid Warfare In Ukraine Ms Threat Intelligence 1 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Desertblade (report)