DesertBlade is a destructive wiper malware used against Ukraine during Russia’s 2022 invasion. Microsoft described it as a limited destructive attack affecting a single Ukrainian entity in early March 2022, with reported deployments on March 1 and again around March 17, 2022. The malware is implemented in Golang and was deployed via hijacked Active Directory Group Policy Objects (GPOs). Its file-destruction behavior overwrites and then deletes files on accessible drives, while sparing the system if it is a domain controller. Public reporting places DesertBlade among the set of wiper families used in destructive activity against Ukrainian targets, alongside WhisperGate, HermeticWiper/HermeticRansom, CaddyWiper, IsaacWiper, Industroyer2, and DoubleZero. The broader reporting states Russian-linked threat actors used such malware against Ukrainian government, financial, energy, IT, military, economic, and communications-related targets, but the provided content does not attribute DesertBlade to a specific actor with confidence. High-confidence indicators directly mentioned in the content include sample hashes a71c8306b6b8a89c18dea3b1490037593737d59b023000f24da94e3275600b59 and 4ca63406ff189301ccbb54daa6e2da4bc5d03ffc1a8a9756717d95d26abc3906. Microsoft also published a YARA rule named DesertBlade based on strings observed in the samples.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct technique documented for this family, organized by ATT&CK tactic.
Following Russia’s invasion of Ukraine on 24 February 2022, likely Russian threat actors conducted several disruptive and destructive computer network attacks against Ukrainian targets... To date, there are eight tracked malware families that Russia-linked cyber threat actors have used for destructive activity against Ukraine: WhisperGate/Whisperkill, FoxBlade (HermeticWiper), SonicVote (HermeticRansom), CaddyWiper, DesertBlade, Industroyer2, Lasainraw (IsaacWiper) and FiberLake (DoubleZero).
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Golang-based destructive wiper deployed via hijacked GPOs; overwrites and deletes files on accessible drives while sparing domain controllers.
Destructive wiper reportedly deployed in early/mid March 2022 against Ukrainian targets.
A year of Russian hybrid warfare in Ukraine CaddyWiper DesertBlade DoubleZero HermeticWiper ...
DesertBlade [[URL_b3187638_138]] 2022 年 4 月 (v 5.100)
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.