FoxBlade is Microsoft’s detection/tracking name for the destructive malware more widely known as HermeticWiper; the content also associates it with the alias HermeticWizard. It was used against Ukrainian targets in the opening phase of Russia’s 2022 invasion of Ukraine, with Microsoft reporting it was launched against computers in Ukraine on February 23, 2022, hours before the kinetic invasion, and that it was discovered on February 23, 2022 impacting hundreds of systems. Reported victim sectors included government, IT, financial, and energy organizations predominantly located in or tied to Ukraine. The malware is described as a wiper/destructive malware used to compromise initial systems and then spread to destroy software and data on additional systems. Microsoft attributed events associated with FoxBlade with medium confidence to IRIDIUM, a cluster associated with Seashell Blizzard/Sandworm/GRU Unit 74455. The Canadian Centre for Cyber Security also lists FoxBlade/HermeticWiper among the destructive malware families used by Russia-linked actors against Ukraine. The content places FoxBlade among notable destructive operations associated with Seashell Blizzard alongside KillDisk and other Ukraine-focused attacks. No specific standalone IOCs for FoxBlade are provided in the content beyond its aliases and attribution context.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Seashell Blizzard’s prolific operations include destructive attacks such as KillDisk (2015) and FoxBlade (2022)...
2 distinct techniques documented for this family, organized by ATT&CK tactic.
On execution, PathWiper replaces the contents of artifacts related to the file system with random data generated on the fly... PathWiper then overwrites the contents/data related to these artifacts directly on disk with random data... PathWiper also destroys files on disk by overwriting them with randomized bytes.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Destructive malware used in attacks attributed to Seashell Blizzard.
Destructive wiper malware used in the opening hours of Russia’s 2022 invasion of Ukraine, intended to damage/erase software and data on targeted Ukrainian systems.
Destructive wiper capability used in attacks impacting hundreds of systems, predominately in or tied to Ukraine.
Destructive malware referenced as part of Seashell Blizzard/Sandworm activity; used in disruptive operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.