HermeticWizard is a custom Windows worm used in the destructive Hermetic malware campaign that targeted Ukrainian organizations around the start of Russia’s 2022 invasion. Its primary role is to propagate the HermeticWiper payload across local networks, while the related HermeticRansom component functioned largely as a decoy ransomware element in the same operations. The malware family naming is associated with certificates issued to Hermetica Digital, and HermeticWizard samples were reported as signed with valid certificates assigned to that name.
HermeticWizard is designed for internal network propagation rather than standalone destruction. It performs local network discovery by enumerating reachable systems and gathering host information through multiple Windows networking APIs. It also includes port-scanning capability to identify accessible targets inside compromised environments. For lateral movement, it leverages SMB and WMI, including remote process creation over WMI, and can authenticate to SMB shares using embedded credential material. On remote hosts it executes malicious payloads through regsvr32, using DLL-based execution to deploy HermeticWiper. The malware has also been observed masquerading as a legitimate Outlook-related DLL name to reduce suspicion.
Operational reporting consistently places HermeticWizard in attacks against Ukrainian networks, where it was used to spread the wiper laterally after initial compromise had already been achieved through other means. Its behavior reflects a purpose-built propagation utility supporting destructive operations against enterprise Windows environments rather than financial crime objectives.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
Both ESET and Symantec detail a combination of WMI/SMB techniques; in particular, the decoded PowerShell commands used to download and execute foreign artifacts follow a structure consistent with a tool known to ease the deployment of semi-interactive shells.
the decoded PowerShell commands used to download and execute foreign artifacts follow a structure consistent with a tool known to ease the deployment of semi-interactive shells: cmd.exe /Q /c powershell -c “(New-Object System.Net.WebClient).DownloadFile(...)”
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.
Akira has used legitimate names and locations for files to evade defenses.
“APT28 has cleared event logs, including by using the commands wevtutil cl System and wevtutil cl Security …” / “APT38 clears Window Event logs and Sysmon logs …” / “BlackCat can clear Windows event logs using wevtutil.exe …” / “NotPetya uses wevtutil to clear the Windows event logs …”
The content repeatedly describes threat actors and malware using valid, stolen, forged, self-signed, or abused code-signing certificates to sign malware and appear legitimate, including examples such as AppleJeus using a valid digital signature from Sectigo, APT41 leveraging code-signing certificates, FIN7 signing Carbanak payloads, and SUNBURST being digitally signed by SolarWinds.
Earth Lusca used the command powershell "Get-EventLog -LogName security -Newest 500 | where {$_.EventID -eq 4624} | format-list - property * | findstr "Address"" to find the network information of successfully logged-in accounts to discovery addresses of other machines.
HermeticWizard is the tool that leverages WMI and SMB in order to spread to additional hosts.
Both ESET and Symantec detail a combination of WMI/SMB techniques... the structure of the command redirects the output (>) to a temporary file located in the ADMIN$ share which is then accessible by the user account with local administrator privileges.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
38 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A worm-like spreading component used to deploy HermeticWiper across reachable devices.
Referenced via YARA as malware associated with the Hermetic campaign; the linked description in the rule metadata identifies it as a worm targeting Ukraine.
Named in additional resources only; no behavioral detail provided in the content body.
Associated component in the Hermetic malware cluster, listed in the IOC section alongside HermeticWiper samples.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.