Destructive malware operations against organizations in Ukraine included CaddyWiper and a separate pseudo-ransomware campaign that posed as extortion but was built to permanently destroy data. Researchers said CaddyWiper shared no code with earlier payloads such as HermeticWiper, but it similarly targeted user files, mapped drives, and disk partitions while avoiding execution on primary domain controllers through a domain-controller kill switch. U.S. authorities warned that multiple malware families were being used in coordinated attacks on Ukrainian networks, underscoring the risk of disruptive and irreversible data loss.
Technical analysis showed the attacks relied on enterprise compromise and staged payload delivery rather than simple smash-and-grab deployment. CaddyWiper checked domain-controller status via the DsRolePrimaryDomainInformation API and wiped disks using low-level Windows functions, while defenders observed destructive payloads being pushed at scale through compromised Group Policy Objects after attackers obtained domain administrator access. In the pseudo-ransomware case, the intrusion chain used an MBR wiper, a downloader retrieving payloads from Discord CDN, a .NET loader that disabled Microsoft Defender and used process hollowing, and a final C-based wiper that overwrote files across 191 extensions before shutting systems down, leaving victims with no practical recovery path despite the ransom note.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Truesec published an analysis of the CaddyWiper wiper used against targets in Ukraine and released a YARA rule named caddy_wiper for detection. The report described the malware's domain-controller check, file and raw-disk destruction behavior, and noted the analyzed sample was compiled on March 14, 2022.
IBM Security X-Force published the XFTI_CaddyWiper YARA rule to detect the CaddyWiper malware family. The rule metadata includes a creation date of 15 March 22 and references a sample named caddy.exe with its SHA-256 hash.
The first reported samples and indicators from a destructive malware campaign targeting Ukraine appeared late in the evening UTC on January 13, 2022. Trellix later assessed the operation as pseudo-ransomware because its final payload irreversibly destroyed data rather than enabling recovery.
Splunk published the "Ransomware Investigate and Contain" response playbook for investigating and containing ransomware on endpoints. The playbook lists required SOAR integrations including Palo Alto Networks Firewall, WildFire, LDAP, and Carbon Black Response.
CISA published an updated alert titled "Destructive Malware Targeting Organizations in Ukraine." The reference indicates an official U.S. government update on the malware threat affecting Ukrainian organizations.
Splunk published a threat update stating that ESET had recently discovered the destructive malware payload CaddyWiper in malicious cyber activity targeting Ukraine. The report said CaddyWiper shared no code with earlier payloads such as HermeticWiper and described its domain-controller kill switch and GPO-based deployment context.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
trellix.com
Open sourcecisa.gov
Open sourcesplunk.com
Open sourceesentire.com
Open sourcetruesec.com
Open sourcesecurityaffairs.co
Open sourcewelivesecurity.com
Open sourcesecurityintelligence.com
Open sourceresearch.splunk.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.