• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
Cyber Security News

Ukrainian Targets Hit by Another Destructive Malware Variant

You are here: Home / General Cyber Security News / Ukrainian Targets Hit by Another Destructive Malware Variant
March 15, 2022

Security researchers have found out nevertheless a different damaging malware variant focusing on Ukrainian devices, the fourth so much this calendar year.

ESET claimed to have built the discover yesterday, noting that the “CaddyWiper” malware was seen on a several dozen units in a “limited number” of businesses.

The malware, which erases user facts and partition information and facts from connected drives, does not share any code similarities with the earlier variants found out by ESET: HermeticWiper and IsaacWiper.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


The code was not digitally signed and is not reminiscent of any other malware ESET has detected in the earlier, the security vendor mentioned.

“Similarly to HermeticWiper deployments, we noticed CaddyWiper becoming deployed via GPO, indicating the attackers had prior manage of the target’s network beforehand,” it explained in a sequence of tweets.

“Interestingly, CaddyWiper avoids destroying knowledge on domain controllers. This is in all probability a way for the attackers to retain their access inside of the firm whilst continue to disturbing operations.”

Just after analyzing information in the PE header, ESET decided that the malware was deployed the identical day it was compiled.

Whilst HermeticWiper and IsaacWiper had been equally applied in the early times of the Russian invasion, the fourth wiper malware, dubbed “WhisperGate” by Microsoft, was discovered in January.

In connected news, the Ukrainian CERT has warned of a new phishing marketing campaign in which the sender impersonates govt companies to trick end users into clicking on a booby-trapped backlink.

The link will consider end users to a ‘Windows AV update page’ so that they can increase their security, the email statements. In truth, the “BitdefenderWindowsUpdatePackage.exe” will down load and run the “one.exe” file from Discord, which is a Cobalt Strike beacon in disguise.

Cobalt Strike is a reputable pen-testing device for remote accessibility and lateral motion usually utilized by threat actors.

Another executable, “dropper.exe,” prospects to the execution of two additional payloads, in the variety of the GraphSteel backdoor (microsoft-cortana.exe) and GrimPlant backdoor (oracle-java.exe).


Some parts of this posting are sourced from:
www.infosecurity-journal.com

Previous Post: «Cyber Security News Clearview AI Helping the Ukrainian War Effort
Next Post: Vodafone and Ericsson complete UK’s first 5G network slicing trial vodafone and ericsson complete uk's first 5g network slicing trial»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Qilin Ransomware Adds “Call Lawyer” Feature to Pressure Victims for Larger Ransoms
  • Iran’s State TV Hijacked Mid-Broadcast Amid Geopolitical Tensions; $90M Stolen in Crypto Heist
  • 6 Steps to 24/7 In-House SOC Success
  • Massive 7.3 Tbps DDoS Attack Delivers 37.4 TB in 45 Seconds, Targeting Hosting Provider
  • 67 Trojanized GitHub Repositories Found in Campaign Targeting Gamers and Developers
  • New Android Malware Surge Hits Devices via Overlays, Virtualization Fraud and NFC Theft
  • BlueNoroff Deepfake Zoom Scam Hits Crypto Employee with MacOS Backdoor Malware
  • Secure Vibe Coding: The Complete New Guide
  • Uncover LOTS Attacks Hiding in Trusted Tools — Learn How in This Free Expert Session
  • Russian APT29 Exploits Gmail App Passwords to Bypass 2FA in Targeted Phishing Campaign

Copyright © TheCyberSecurity.News, All Rights Reserved.