PathWiper

First seen
2022-01-01 00:00:00
Malware type
wiper
Family
Malware family
Profile updated
2026-07-07 15:15:16

Context

According to Cisco Talos, this wiper replaces the contents of artifacts related to the file system with random data generated on the fly. It identifies connected storage media, creates one thread per drive and volume for every path recorded and overwrites artifacts with randomly generated bytes. The wiper also reads multiple file systems attributes from NTFS and overwrites them as well. PathWiper additionally destroys files on disk by overwriting them with randomized bytes.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Pathwiper_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Pathwiper (report)
  • Cisco Talos — Pathwiper Targets Ukraine (report)

External references