WhisperGate is a destructive Windows wiper first observed in January 2022 in targeted attacks against Ukrainian organizations. It masquerades as ransomware by overwriting the master boot record and presenting a ransom-style message after reboot, but its purpose is irreversible disruption rather than extortion. A subsequent destructive component overwrites targeted files on local, removable, and connected remote drives, including mounted logical drives, rendering data unrecoverable. Microsoft tracked the activity as DEV-0586. WhisperGate uses a staged loader that retrieves an in-memory payload through Discord-hosted infrastructure. It employs PowerShell and Visual Basic scripting to impair Microsoft Defender protections, checks for monitoring tools, and uses process hollowing to run its final payload within a legitimate Windows process. The campaign coincided with website defacements and other disruptive activity against Ukrainian government-related targets amid the Russia-Ukraine conflict.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Cyberattack using WhisperGate... WhisperGate: This malware downloads and executes additional payload from the C&C server constructed on Discord.
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Vladislav Yevgenyevich Borovkov ... officier GRU affecté à l’Unité militaire 29155 ... associé à la campagne WhisperGate.
Recent cyber activity attributed to Russian State actors includes website defacement and wiper malware (WhisperGate) attacks.
Microsoft warned of destructive data-wiping malware disguised as ransomware being used in attacks against multiple organizations in Ukraine. The company, which is calling this new malware family WhisperGate, attributed it to a threat cluster it's tracking as DEV-0586.
The Conspirators infected computers on these and other networks with malware called WhisperGate, which was designed to look like ransomware. However, as the indictment alleges, WhisperGate was actually a cyberweapon designed to completely destroy the target computer and related data.
The group is also known to have performed the WhisperGate disruptive attack against the Ukrainian government entities in early 2022.
Starting on January 13th, 2022, several Ukrainian organizations were hit with a destructive malware now known as WhisperGate.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
reports from several entities, including the Ukrainian CERT, provide enough context to identify general behaviors and techniques used by the adversary: Use of compromised credentials to access victim environments via single-factor authentication | Use of compromised credentials to access victim environments via single-factor authentication
The content repeatedly describes threat actors and malware using PowerShell to execute payloads, run commands, download additional malware, perform lateral movement, evade defenses, and execute scripts in memory. | Examples include: 'APT28 downloads and executes PowerShell scripts and performs PowerShell commands'; 'APT3 has used PowerShell on victim systems to download and run payloads after exploitation'; 'TA505 has used PowerShell to download and execute malware and reconnaissance scripts.'
reports from several entities, including the Ukrainian CERT, provide enough context to identify general behaviors and techniques used by the adversary: Use of compromised credentials to access victim environments via single-factor authentication | Use of compromised credentials to access victim environments via single-factor authentication
This file is used to create the host process where the final wiper payload is injected, using a technique known as process hollowing.
Agent Tesla has used process hollowing to create and manipulate processes through sections of unmapped memory by reallocating that space with its malicious code. APT-C-36 has used process hollowing to execute malware in the memory of legitimate processes. Astaroth can create a new process in a suspended state from a targeted legitimate process in order to unmap its memory and replace it with malicious code.
reports from several entities, including the Ukrainian CERT, provide enough context to identify general behaviors and techniques used by the adversary: Use of compromised credentials to access victim environments via single-factor authentication | Use of compromised credentials to access victim environments via single-factor authentication
The file byte order is reversed, likely to evade detection by host-based controls. The loader restores the byte order and then performs multiple rounds of extraction and decoding of nested resources to get to the final malicious code.
Although the payload's filename suggests that it is a JPG image file, it is a DLL file.
This file is used to create the host process where the final wiper payload is injected, using a technique known as process hollowing.
Agent Tesla has used process hollowing to create and manipulate processes through sections of unmapped memory by reallocating that space with its malicious code. APT-C-36 has used process hollowing to execute malware in the memory of legitimate processes. Astaroth can create a new process in a suspended state from a targeted legitimate process in order to unmap its memory and replace it with malicious code.
The code also included a function that runs a command (cmd.exe /min /C ping 111.111.111.111 -n 5 -w 10 > Nul & Del /f /q "%s") that uses ping to inject a brief time delay before deleting a file.
reports from several entities, including the Ukrainian CERT, provide enough context to identify general behaviors and techniques used by the adversary: Use of compromised credentials to access victim environments via single-factor authentication | Use of compromised credentials to access victim environments via single-factor authentication
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
Examples include: "Babuk can enumerate disk volumes," "Confucius has used a file stealer that can examine system drives," and "XAgentOSX contains the getInstalledAPP function to run ls -la /Applications to gather what applications are installed."
APT1 listed connected network shares. APT32 used the net view command to show all shares available, including the administrative shares such as C$ and ADMIN$. APT41 used the net share command as part of network reconnaissance.
Recent cyber activity attributed to Russian State actors includes website defacement and wiper malware (WhisperGate) attacks.
the attack is believed to have been carried out after the malicious actors gained access to the infrastructure of a private company that had the rights to manage some of the affected websites. Separately, Microsoft warned of destructive data-wiping malware disguised as ransomware being used in attacks against multiple organizations in Ukraine.
When both the website defacements and the first WhisperGate malware deployments occurred in mid-January, we were contacted by three Ukrainian government agencies we have worked with in the past.
29 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
150 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware/campaign referenced only in connection with GRU officer Vladislav Borovkov and Unit 29155; no technical behavior is described in the content.
Disruptive wiper malware associated in the article with the same threat actor's earlier attacks on Ukrainian government entities.
Destructive malware used to deface and disrupt Ukrainian government systems ahead of Russia's 2022 invasion.
Wiper malware intended to delete data from infected systems; attributed here to GRU unit 29155 and noted as having hit Ukraine in 2022.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.