• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
caddywiper: yet another data wiping malware targeting ukrainian networks

CaddyWiper: Yet Another Data Wiping Malware Targeting Ukrainian Networks

You are here: Home / General Cyber Security News / CaddyWiper: Yet Another Data Wiping Malware Targeting Ukrainian Networks
March 15, 2022

Two months just after details emerged about a 2nd data wiper pressure delivered in attacks against Ukraine, yet an additional harmful malware has been detected amid Russia’s continuing military invasion of the country.

Slovak cybersecurity company ESET dubbed the 3rd wiper “CaddyWiper,” which it said it initial noticed on March 14 all over 9:38 a.m. UTC. Metadata associated with the executable (“caddy.exe”) reveals that the malware was compiled at 7:19 a.m. UTC, a minimal above two hours prior to its deployment.

“This new malware erases consumer details and partition information and facts from hooked up drives,” the enterprise mentioned in a tweet thread. “ESET telemetry reveals that it was viewed on a number of dozen programs in a minimal quantity of companies.”

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper take secure and enxrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized seller: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


Automatic GitHub Backups

CaddyWiper is notable for the simple fact that it isn’t going to share any similarities with formerly found out wipers in Ukraine, which includes HermeticWiper (aka FoxBlade or KillDisk) and IsaacWiper (aka Lasainraw), the two of which have been deployed in methods belonging to authorities and commercial entities.

As opposed to CaddyWiper, both the HermeticWiper and IsaacWiper malware families are claimed to have been in growth for months in progress in advance of their release, with oldest identified samples compiled on December 28 and Oct 19, 2021, respectively.

Data Wiping Malware

But the recently found wiper shares a person tactical overlap with HermeticWiper in that the malware, in just one occasion, was deployed via the Windows domain controller, indicating that the attackers had taken regulate of the Lively Listing server.

“Apparently, CaddyWiper avoids destroying information on area controllers,” the corporation mentioned. “This is probably a way for the attackers to maintain their obtain inside the group while still disturbing functions.”

Microsoft, which has attributed the HermeticWiper attacks to a threat cluster tracked as DEV-0665, claimed the “supposed goal of these attacks is the disruption, degradation, and destruction of qualified sources” in the country.

Prevent Data Breaches

The growth also arrives as cybercriminals have opportunistically and more and more capitalized on the conflict to style phishing lures, which include themes of humanitarian guidance and numerous sorts of fundraising, to provide a range of backdoors these types of as Remcos.

“The global curiosity in the ongoing war in Ukraine helps make it a hassle-free and powerful information event for cybercriminals to exploit,” Cisco Talos researchers reported. “If a specified matter of lure is heading to maximize the likelihood of a likely victim installing their payload, they will use it.”

But it really is not just Ukraine that’s been at the receiving stop of wiper attacks. Past week, cybersecurity firm Pattern Micro disclosed specifics of a .NET-primarily based wiper named RURansom that has exclusively focused entities in Russia by encrypting the files with a randomly created cryptographic crucial.

“The keys are exclusive for each encrypted file and are not stored wherever, producing the encryption irreversible and marking the malware as a wiper alternatively than a ransomware variant,” the scientists noted.

Uncovered this write-up appealing? Follow THN on Fb, Twitter  and LinkedIn to study more exceptional articles we put up.


Some areas of this write-up are sourced from:
thehackernews.com

Previous Post: «massive ddos attack knocked israeli government websites offline Massive DDoS Attack Knocked Israeli Government Websites Offline
Next Post: Clearview AI Helping the Ukrainian War Effort Cyber Security News»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • New “B1txor20” Linux Botnet Uses DNS Tunnel and Exploits Log4J Flaw
  • New Infinite Loop Bug in OpenSSL Could Let Attackers Crash Remote Servers
  • FBI, CISA Warn of Russian Hackers Exploiting MFA and PrintNightmare Bug
  • Unpatched RCE Bug in dompdf Project Affects HTML to PDF Converters
  • NortonLifeLock and Avast merger could reduce competition, CMA warns
  • Thousands of Mobile Apps Expose User Data Via Cloud Misconfigurations
  • NSW ditches e-voting system for 2023 election
  • Kaspersky Hits Back at “Politically Motivated” BSI Advisory
  • Germany advises against using Kaspersky software due to hacking risk
  • CISA: Fix MFA and Patch Promptly to Stop Russian Attackers

Copyright © TheCyberSecurity.News, All Rights Reserved.