PathWiper is a destructive Windows wiper malware used in attacks against critical infrastructure organizations in Ukraine. It is designed to render systems unbootable and data unrecoverable by systematically discovering connected storage media, dismounting volumes, and overwriting critical disk structures and files with randomized data. Observed behavior includes enumeration of physical drives, volumes, and network drive paths, including previously mapped shared drives, followed by parallelized destruction across identified targets. The malware corrupts the master boot record and multiple NTFS metadata structures, and also overwrites files on disk, indicating an intent to maximize operational disruption rather than support espionage or monetization.
PathWiper has been observed deployed through a legitimate endpoint administration framework, with attackers issuing malicious commands through the management infrastructure to execute a script-based staging chain that drops and launches the wiper payload. The intrusion tradecraft suggests prior access to administrative tooling and familiarity with the victim environment, and the staging activity was crafted to resemble legitimate administrative operations to reduce suspicion.
The malware has been assessed with high confidence as linked to a Russia-nexus advanced persistent threat operation targeting Ukrainian entities. Multiple reports note functional and semantic similarities to HermeticWiper, another destructive malware family used against Ukraine and widely associated with Sandworm. Dragos linked PathWiper to ELECTRUM with moderate confidence. PathWiper is notable for a more deliberate drive and volume discovery process than some earlier wipers, including validation of storage records before destruction, which is consistent with carefully targeted disruptive operations against critical infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"researchers identified a destructive malware family called PathWiper, linked by Dragos to ELECTRUM with moderate confidence."
13 distinct techniques documented for this family, organized by ATT&CK tactic.
It first gathers a list of connected storage media on the endpoint, including: Physical drive names Volume names and paths Network shared and unshared (removed) drive paths
The BAT file consisted of a command to execute a malicious VBScript file called ‘uacinstall.vbs’, also pushed to the endpoint by the administrative console... Upon execution, the VBScript wrote the PathWiper executable, named ‘sha256sum.exe’, to disk and executed it.
On execution, PathWiper replaces the contents of artifacts related to the file system with random data generated on the fly... PathWiper then overwrites the contents/data related to these artifacts directly on disk with random data... PathWiper also destroys files on disk by overwriting them with randomized bytes.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Wiper malware targeting Ukrainian organizations.
A destructive wiper malware referenced as the analytic story associated with this detection; the content links this Excel/DCOM child-process behavior to PathWiper-related tradecraft.
Destructive wiper malware that enumerates mounted volumes and overwrites filesystem structures across accessible storage media to cause irreversible data loss.
Wiper malware family used in destructive attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.