• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
Cyber Security News

Ukrainian Targets Hit by Another Destructive Malware Variant

You are here: Home / General Cyber Security News / Ukrainian Targets Hit by Another Destructive Malware Variant
March 15, 2022

Security researchers have found out nevertheless a different damaging malware variant focusing on Ukrainian devices, the fourth so much this calendar year.

ESET claimed to have built the discover yesterday, noting that the “CaddyWiper” malware was seen on a several dozen units in a “limited number” of businesses.

The malware, which erases user facts and partition information and facts from connected drives, does not share any code similarities with the earlier variants found out by ESET: HermeticWiper and IsaacWiper.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


The code was not digitally signed and is not reminiscent of any other malware ESET has detected in the earlier, the security vendor mentioned.

“Similarly to HermeticWiper deployments, we noticed CaddyWiper becoming deployed via GPO, indicating the attackers had prior manage of the target’s network beforehand,” it explained in a sequence of tweets.

“Interestingly, CaddyWiper avoids destroying knowledge on domain controllers. This is in all probability a way for the attackers to retain their access inside of the firm whilst continue to disturbing operations.”

Just after analyzing information in the PE header, ESET decided that the malware was deployed the identical day it was compiled.

Whilst HermeticWiper and IsaacWiper had been equally applied in the early times of the Russian invasion, the fourth wiper malware, dubbed “WhisperGate” by Microsoft, was discovered in January.

In connected news, the Ukrainian CERT has warned of a new phishing marketing campaign in which the sender impersonates govt companies to trick end users into clicking on a booby-trapped backlink.

The link will consider end users to a ‘Windows AV update page’ so that they can increase their security, the email statements. In truth, the “BitdefenderWindowsUpdatePackage.exe” will down load and run the “one.exe” file from Discord, which is a Cobalt Strike beacon in disguise.

Cobalt Strike is a reputable pen-testing device for remote accessibility and lateral motion usually utilized by threat actors.

Another executable, “dropper.exe,” prospects to the execution of two additional payloads, in the variety of the GraphSteel backdoor (microsoft-cortana.exe) and GrimPlant backdoor (oracle-java.exe).


Some parts of this posting are sourced from:
www.infosecurity-journal.com

Previous Post: «Cyber Security News Clearview AI Helping the Ukrainian War Effort
Next Post: Vodafone and Ericsson complete UK’s first 5G network slicing trial vodafone and ericsson complete uk's first 5g network slicing trial»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.