GermanWiper is a destructive pseudo-ransomware campaign identified in July 2019. Although it presents itself as ransomware and drops a German-language HTML ransom note demanding 0.15038835 BTC, it does not encrypt files; instead, it irreversibly overwrites affected files with zeros, making recovery impossible. The malware was dubbed "GermanWiper" by Michael Gillespie because of this wiping behavior.
The campaign was distributed via German-language phishing emails themed as job applications. Malicious attachments were Windows shortcut files using a double-extension technique to masquerade as Microsoft Word documents, including names such as "Lebenslauf Aktuell.doc.lnk" and "Arbeitszeugnisse Aktuell.doc.lnk." The phishing emails and ransom note were written in German without umlauts. Execution involved PowerShell and HTA mechanisms, and the ransom note contained a PHP script used for communication with attacker infrastructure.
GermanWiper also executed vssadmin.exe to delete shadow copies and system restore points, disabled recovery options at startup, and created persistence entries in the Start Menu and msconfig autostart so the ransom note would reopen after reboot. The malware skipped certain files and directories during destruction, including Windows, Program Files, ProgramData, AppData, System Volume Information, boot-related files, and common system metadata files.
Observed infrastructure and indicators associated with the campaign include 173.33.106.120 hosted at OVH, moneymaker[.]software, and expandingdelegation[.]top, the latter resolving to 8.208.13.24 and referenced in a later ransom note, suggesting a possible second wave by 2019-08-02. Reported file hashes include SHA-256 41364427dee49bf544dcff61a6899b3b7e59852435e4107931e294079a42de7c for a later sample; SHA-1 8cd96603cdd2637cf5469aba8ed2b149c35ef699 for the malware executable; SHA-1 058ad51c8eb86545a5424c0b021235da3bbce1c8 for an associated ZIP archive; SHA-1 2d8f89693d14b9ea7a056bced983dfc88fe76105 for "Doris Sammer - Arbeitszeugnisse Aktuell.doc.lnk"; and SHA-1 77d5224fc02999b04ab79054aad23b0f6213b7eb for "Doris Sammer - Lebenslauf Aktuell.doc.lnk." Malspam sender domains included rasendmail.com, stadtmailer.com, nrwmail.com, and mailplatz.com.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named ransomware/wiper family mentioned for comparison with Sodinokibi.
A destructive pseudo-ransomware/wiper delivered via malicious LNK attachments that masquerade as Office documents. It drops and runs payloads, deletes shadow copies and restore points, establishes persistence to display an HTML ransom note, and overwrites targeted files with zeros, making recovery impossible.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.