Cisco Talos disclosed a destructive intrusion against a Ukrainian critical infrastructure organization in which attackers deployed a newly identified wiper malware family, PathWiper, after allegedly gaining access to a legitimate endpoint administration framework. Talos said the operation bears strong similarities to prior Russia-linked attacks on Ukraine and assessed with high confidence that a Russia-nexus APT actor was responsible. The malware was launched via a dropped VBScript, uacinstall.vbs, which wrote sha256sum.exe to disk and then systematically corrupted physical drives, volumes, NTFS artifacts, and files with random data after attempting to dismount targeted volumes.
The reporting indicates the attackers used enterprise administration mechanisms to issue malicious commands and likely relied on established lateral movement techniques before the destructive phase. Related defensive research has highlighted how Microsoft Excel can be abused through DCOM for remote execution and lateral movement, and Splunk has published detection guidance for suspicious cases where Excel spawns unusual child processes, a pattern that can indicate Office-based execution or command-and-control activity. Talos noted that PathWiper shares semantic similarities with HermeticWiper but uses a more methodical drive and network-share discovery process, including enumeration of removed shared drives through the Windows registry.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
Splunk Threat Research removed the detection "Windows Excel ActiveMicrosoftApp Child Process" and replaced it with the renamed analytic "Windows Excel Spawning Microsoft Project Application" in content library version 5.26.0. The detection was associated with the PathWiper analytic story and mapped to DCOM lateral movement tradecraft.
Splunk Threat Research removed the deprecated detection analytic "Office Product Spawning CertUtil" from its content library because it no longer effectively identified the intended malicious activity. Splunk listed "Windows Office Product Spawned Uncommon Process" as the replacement and recorded the change in content library version 5.2.0.
Talos disclosed technical details on PathWiper's execution chain and destructive behavior, including its use of a VBScript dropper, the sha256sum.exe payload name, and overwriting of MBR and NTFS artifacts. Talos also published an indicator of compromise for the malware: 7C792A2B005B240D30A6E22EF98B991744856F9AB55C74DF220F32FE0D00B6B3.
SpecterOps published research describing lateral movement through abuse of the DCOM Excel Application. This research was later cited by Splunk in detection content مرتبط with PathWiper-related tradecraft.
Cisco Talos reported observing a destructive attack against a critical infrastructure entity in Ukraine and identified a previously unknown wiper malware family, which it named PathWiper. Talos said the attackers used a legitimate endpoint administration framework to issue malicious commands and deploy the wiper, and attributed the operation with high confidence to a Russia-nexus APT actor.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
research.splunk.com
Open sourceresearch.splunk.com
Open sourceblog.talosintelligence.com
Open sourcespecterops.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.