HermeticWiper is a destructive Windows data wiper deployed against Ukrainian government, financial, and other high-profile organizations immediately before Russia’s full-scale invasion of Ukraine in February 2022. Also tracked as DriveSlayer and Trojan.Killdisk, it was used against hundreds of systems and is associated with the UAC-0082 activity cluster. The malware’s primary purpose is sabotage: it corrupts physical-drive boot records, partition metadata, filesystem structures, and selected file data, then forces a restart or shutdown to render affected hosts unbootable and data unavailable. HermeticWiper abuses legitimate partition-management drivers to obtain low-level raw-disk access, installs a kernel-mode service for driver communication, and selects embedded driver variants based on the Windows version and architecture. It enumerates accessible disks and NTFS or FAT volumes, overwrites targeted sectors and filesystem artifacts with random data, and targets recovery-related data. It also disables crash-dump generation and Volume Shadow Copy functionality, impeding recovery and forensic analysis, while modifying Windows settings to reduce visible signs of compression or encryption. HermeticWiper lacks an identified built-in network command-and-control or self-propagation mechanism; observed deployments included distribution through Active Directory Group Policy from already compromised domain environments. It was deployed alongside the flawed HermeticRansom, also known as PartyTicket, which appears to have served as a decoy rather than a genuine extortion payload. Although the operations occurred in the context of Russian military action against Ukraine, public reporting did not conclusively attribute HermeticWiper to a specific threat actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Symantec in their analysis reported two different exploits used in the attacks carried out against the investigated targets: one targeting Microsoft SQL Server (CVE-2021-1636) and another affecting Apache Tomcat. | researchers at ESET have identified a series of components that, together, worked to cripple Ukrainian target networks: HermeticWiper, HermeticWizard, and HermeticRansom. HermeticWiper is the destructive payload
9 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
On February 23, 2022, the ESET threat research team disclosed findings pertaining to a Data Wiper malware campaign impacting hundreds of systems across Ukraine, named HERMETICWIPER.
On February 23, 2022, the ESET threat research team disclosed findings pertaining to a Data Wiper malware campaign impacting hundreds of systems across Ukraine, named HERMETICWIPER.
...cyber offensives targeting Ukraine that resulted in the deployment of a data wiper called HermeticWiper on hundreds of machines in the East European nation.
HermeticWiper is a sophisticated malware family that is designed to destroy data and render a system inoperable.
CaddyWiper is notable for the fact that it doesn't share any similarities with previously discovered wipers in Ukraine, including HermeticWiper (aka FoxBlade or KillDisk) and IsaacWiper (aka Lasainraw).
28 distinct techniques documented for this family, organized by ATT&CK tactic.
“Suspicious Cmd Execution via WMI (Deployment of wiper via Impacket WMI).”
The HermeticWiper has been executed via a scheduled task on the victimized devices, as reported by Symantec.
The HermeticWiper has been executed via a scheduled task on the victimized devices, as reported by Symantec.
“HERMETICWIPER also modifies two registry settings during execution (ShowCompColor and ShowInfoTip), setting those key values to 0.”
The HermeticWiper has been executed via a scheduled task on the victimized devices, as reported by Symantec.
Hermetic Wiper will then elevate its privileges to SeLoadDriverPrivilege and load the driver and start it as a service.
According to ESET, the infection mechanism is similar to the HermeticWiper malware in that it operates via Default Domain Policy.
Create a service for the dropped epmntdrv.sys to finally load the driver.
“Upon execution, HERMETICWIPER creates a kernel mode service and interacts with it via DeviceIoControl API function.”
Up next is the check for both the above-mentioned privilege, as well as “SeBackupPrivilege”. The two privileges are then requested using AdjustTokenPrivileges... Next, the wiper attempts to acquires the “SeLoadDriverPrivilege” privilege. If this permission is not granted, the malware terminates itself.
One modification disables crash dumps by setting HKLM\SYSTEM\ControlSet001\Control\CrashControl\CrashDumpEnabled to 0. This change is likely to reduce forensic artifacts if the malware causes the system to stop unexpectedly.
Unlike HermeticWiper and ransomware like LockBit, DoubleZero doesn’t delete the shadow copies that can possibly be used to recover files from the damage.
The driver is embedded (compressed using the MSLZ format) into the wiper’s resources... The compressed driver is then loaded from the resources, and written to “C:\WINDOWS\system32\drivers\[XX]dr”... The compressed file is then read from the disk, decompressed, and written to disk using the same file name, with “.sys” added to it.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
“The main objective is to corrupt any attached physical drive and render the system data unrecoverable.”
“The System Volume information direct used to store Windows restore points” is listed among items targeted for shredding.
The destruction of the file system, rather than files within the file system, makes it harder to simply restore some files to “repair” the victimized machine.
the wiper runs a version of the EaseUS Partition Master software, a disk partitioning utility, which it uses to corrupt local data and then reboot the computer | it also damages the master boot record (MBR) section of a hard drive, which prevents the computer from booting into the operating system after the forced reboot
35 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
116 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A 2022 variant mentioned in the family history/updates that is referred to as HermeticWiper and uses legitimate EaseUS Partition Master software to damage disk partitions.
Wiper malware used to destroy or disrupt systems across multiple Ukrainian sectors immediately prior to the 2022 invasion.
Referenced as historical comparison for destructive malware focused on immediate operational impact.
Destructive wiper malware observed in telemetry shortly before the tournament kickoff window.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.