CaddyWiper is a destructive Windows wiper malware family used in attacks against Ukrainian organizations during Russia’s invasion of Ukraine. It is closely associated with Sandworm, the GRU-linked threat actor also tracked as Unit 74455, and has been deployed in disruptive operations affecting sectors including energy, banking, government, and media. The malware has also been used in conjunction with industrial disruption campaigns, including operations involving Industroyer2 against Ukrainian electric power infrastructure, where it was intended to hinder recovery and erase traces in the IT environment after attempted OT impact.
CaddyWiper’s primary purpose is destruction. It overwrites user files, affects mapped drives, and damages physical drive partition information, including boot-relevant structures such as the MBR, GPT, and partition entries, rendering systems unbootable or otherwise inoperable. Reported variants enumerate physical drives and overwrite file contents and partitions with null bytes. The malware has also been described as wiping files related to OT-supporting capabilities in victim IT environments.
A notable behavioral characteristic is its logic to avoid execution on Domain Controllers. Multiple reports state that CaddyWiper checks whether the infected host is a Domain Controller and triggers a killswitch or otherwise refrains from destructive execution in that environment, while proceeding to wipe non-DC systems. This suggests an operational preference to preserve core directory services needed for broader attacker control or coordinated deployment.
CaddyWiper has been delivered inside compromised Windows enterprise environments using administrative mechanisms rather than broad commodity distribution. Sandworm has used Scheduled Tasks, including deployment via Group Policy Objects, to execute CaddyWiper at predetermined times across victim networks. Reporting also describes domain-wide deployment through modified Group Policy and scheduled-task artifacts, indicating post-compromise use after attackers had already obtained substantial control of Active Directory or equivalent administrative access.
The malware has appeared in multiple destructive campaigns from 2022 onward and is one of the most frequently observed GRU disruptive tools used against Ukraine. It has been deployed alongside other wipers and destructive tooling, and public reporting notes continuing refinement across x86, x64, and shellcode variants. In the context of Russian cyber operations, CaddyWiper is part of a broader pattern of coordinated sabotage and recovery-denial activity directed at Ukrainian critical infrastructure and other strategic targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Mandiant previously tied the 2023 blackouts in Ukraine to Sandworm's deployment of CaddyWiper malware.
Notable attacks included the deployment of Industroyer2 against energy facilities and widespread use of CaddyWiper malware.
"...виявлено 5 зразків шкідливих програм (скриптів)... а саме: CaddyWiper (Windows) ..."; "...невдалу спробу... з використанням шкідливих програм-деструкторів CaddyWiper..."
"CADDYWIPER is a wiper that Mandiant first identified and reported on in March 2022... The malware enumerates the file system's physical drives and overwrites both file content and partitions with null bytes."
"CADDYWIPER is a wiper that Mandiant first identified and reported on in March 2022... The malware enumerates the file system's physical drives and overwrites both file content and partitions with null bytes."
18 distinct techniques documented for this family, organized by ATT&CK tactic.
"...створено об'єкт групової політики (GPO), що, у свою чергу, забезпечував створення відповідних запланованих завдань." and "Windows_Security_Update_HxW (Scheduled Task)"
"...створено об'єкт групової політики (GPO), що, у свою чергу, забезпечував створення відповідних запланованих завдань." and "Windows_Security_Update_HxW (Scheduled Task)"
Several entries explicitly tie host profiling to anti-analysis or execution gating, such as 'DarkGate uses ... disk size and physical memory as part of the malware's anti-analysis checks for running in a virtualized environment,' 'OopsIE checks for information on the CPU fan, temperature, mouse, hard disk, and motherboard as part of its anti-VM checks,' and malware terminating or changing behavior based on language or OS/distribution.
The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
"CaddyWiper can use DsRoleGetPrimaryDomainInformation to determine the role of the infected machine. CaddyWiper can also halt execution if the compromised host is identified as a domain controller."
Several entries explicitly tie host profiling to anti-analysis or execution gating, such as 'DarkGate uses ... disk size and physical memory as part of the malware's anti-analysis checks for running in a virtualized environment,' 'OopsIE checks for information on the CPU fan, temperature, mouse, hard disk, and motherboard as part of its anti-VM checks,' and malware terminating or changing behavior based on language or OS/distribution.
After gaining internal access, the attacker conducted reconnaissance and prepared destructive actions including firmware damage, system-file deletion, and custom wiper execution.
"GRU operations... frequently end with the deployment of wipers... CADDYWIPER... overwrites both file content and partitions with null bytes."
“AcidPour can identify various system locations and mapped devices on Linux systems as a precursor to wiping activity.”
APT37 has access to destructive malware that is capable of overwriting a machine's Master Boot Record (MBR). APT38 has used a custom MBR wiper named BOOTWRECK to render systems inoperable. CaddyWiper has the ability to destroy information about a physical drive's partitions including the MBR, GPT, and partition entries.
38 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Destructive wiper malware previously deployed in attacks tied to Ukrainian blackouts.
Wiper deployed in the IT environment alongside Sandworm OT disruption activity in Ukraine.
Wiper malware used against Ukrainian infrastructure as part of Sandworm-attributed campaigns.
Destructive wiper malware previously deployed against Ukrainian networks, including power-supply units.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.