Multiple destructive malware campaigns struck Ukraine around the start of Russia’s invasion, with HermeticWiper, IsaacWiper, CaddyWiper, WhisperGate, and DoubleZero used against government, financial, and other organizations. Researchers reported that HermeticWiper corrupted boot records and partition data by abusing a legitimate EaseUS driver, while CaddyWiper and DoubleZero erased user data, partition information, and critical registry or boot components, often while deliberately sparing domain controllers to preserve attacker access. Several incidents appeared to follow prior compromise of victim networks, including abuse of Active Directory, scheduled execution, and in some cases worm-like spread via HermeticWizard; HermeticRansom was also deployed as a likely decoy alongside destructive activity.
The destructive operations extended beyond enterprise Windows environments. AcidRain was used in the attack on Viasat’s KA-SAT network, wiping satellite modems in Ukraine and elsewhere in Europe by recursively destroying filesystems and storage devices, while the Industroyer2 operation targeted a Ukrainian energy provider with malware built to communicate over IEC-104 and cut power, paired with Windows, Linux, and Solaris wipers including CaddyWiper, ORCSHRED, SOLOSHRED, and AWFULSHRED. Across the reporting, defenders were urged to watch for mass file overwrites, shadow copy and event log deletion, MBR or partition changes, suspicious use of administrative tooling and group policy, and to maintain tested, isolated backups to recover from destructive attacks.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
28 events from the most recent confirmed update back to the earliest known activity.
Trellix published a blog analyzing more than twenty recent wiper malware families, with emphasis on destructive campaigns affecting Ukrainian organizations in early 2022. The research compared families including HermeticWiper, WhisperGate, CaddyWiper, RURansom, dnWipe, AcidRain, and Nominatus_ToxicBattery.
Trellix said it observed an incident in June 2022 in which an actor first attempted to wipe a victim with WhisperGate and later made a second attempt using HermeticWiper. The report highlighted continued reuse of multiple wiper families against the same target.
ESET and CERT-UA published analysis of the attempted attack on a Ukrainian energy provider, naming the malware Industroyer2 and linking it to the 2016 Industroyer lineage. They also disclosed coordinated use of CaddyWiper, ORCSHRED, SOLOSHRED, and AWFULSHRED and attributed the operation to Sandworm with high confidence.
CaddyWiper was scheduled to execute at 16:20 UTC on the same machine used for Industroyer2. ESET said the wiping step was intended to impede recovery and erase traces of the ICS attack.
Industroyer2 was scheduled to execute at 16:10 UTC to disrupt electricity delivery in a Ukrainian region. ESET and CERT-UA later assessed with high confidence that Sandworm was responsible.
A Sandworm operator created a scheduled task at 15:02:22 UTC to launch Industroyer2 on the victim system. The malware was configured to communicate with substation protection relays over IEC-104.
A CaddyWiper variant was deployed against the Ukrainian energy provider at 14:58 UTC as part of the April 8 operation. The attackers used a new loader, ARGUEPATCH, identified as a trojanized Hex-Rays IDA Pro remote debugger server.
Attackers planned destructive actions against a Ukrainian energy provider for April 8, combining ICS malware with coordinated wiping on Windows, Linux, and Solaris systems. ESET said artifacts indicated the operation had been prepared for at least two weeks.
A CaddyWiper deployment hit a Ukrainian governmental entity one week before the attempted power disruption. This showed the malware being reused across multiple Ukrainian targets.
Viasat said SentinelOne's AcidRain analysis matched its own findings that a destructive executable had been run on modems using legitimate management commands. The company said the February 24 KA-SAT attack affected thousands in Ukraine and tens of thousands more across Europe, while finding no evidence of firmware compromise or end-user data theft.
SentinelOne published research on AcidRain, a modem and router wiper tied to the KA-SAT disruption in Europe. The analysis described a 32-bit MIPS ELF malware that recursively wiped filesystems and storage devices before rebooting the device.
The analyzed Industroyer2 sample carried a PE timestamp showing it was compiled on March 23, 2022. ESET later assessed the malware as a new Industroyer variant built for a specific victim environment.
CERT-UA released an advisory warning about DoubleZero and tracked the associated activity as UAC-0088. The advisory stated the malware had been found on March 17 and was intended to disrupt Ukrainian organizations.
Ukraine CERT discovered the DoubleZero Destructor destructive malware and tracked the case as CERT-UA #4243. The .NET wiper was designed to zero files, delete registry data, and render systems unbootable while avoiding domain controllers.
Metadata showed the CaddyWiper executable caddy.exe was compiled at 07:19 UTC, shortly before it was observed in attacks later that morning. This suggested rapid operational deployment after build time.
ESET first discovered CaddyWiper when it was used against a Ukrainian bank. The malware was a distinct destructive wiper that erased user data and partition information and did not closely resemble HermeticWiper or IsaacWiper in code.
Avast released a free GUI-based decryptor to help victims recover files encrypted by HermeticRansom. The tool built on previously disclosed weaknesses in the malware's cryptographic implementation.
ESET published research on IsaacWiper and HermeticWizard, documenting a new wiper and worm targeting Ukraine. The report expanded public technical understanding of the destructive activity following HermeticWiper.
An analyzed IsaacWiper sample named Cleaner.dll carried a compile timestamp of 15:48:07 UTC, indicating the destructive wiper was built days before public reporting. IBM X-Force later analyzed the sample and published detection logic for it.
Symantec reported that disk-wiping malware attacks in Ukraine preceded Russian forces crossing the border. The malware was identified as Trojan.Killdisk, also known as HermeticWiper.
Russia's military invasion of Ukraine began, providing the geopolitical backdrop for the destructive cyber operations described across the references. Several sources explicitly anchor subsequent wiper activity relative to this date.
Researchers observed the first signs of HermeticRansom distribution hours before Russian troops invaded Ukraine. The ransomware was delivered together with the HermeticWizard worm and was assessed as more of a decoy within destructive operations than a profit-driven campaign.
At least 13 Ukrainian government entities were defaced during the same disruptive wave associated with HermeticWiper activity. Secureworks linked the defacements to a Tor site operated by "Free Civilian," though the claimed data theft was unverified.
Security researchers first observed HermeticWiper in Ukraine, where it targeted government and financial organizations. The malware abused a legitimate EaseUS partition manager driver to corrupt boot sectors, partition information, and files.
Disruptive DDoS activity caused intermittent outages at multiple Ukrainian government websites, while PrivatBank and Oschadbank were again targeted. Secureworks said this activity began on February 23, 2022, immediately before the invasion.
ThreatLabz identified a sample uploaded from Ukraine that led to discovery of a previously undocumented second intrusion chain linked to targeted attacks. The broader activity was assessed with moderate confidence as the work of the same actor behind another January-February chain.
Microsoft released a report about a wiper targeting Ukraine, documenting the WhisperGate attack chain. Later analysis focused on recovering the final wiper payload from its staged loader sequence.
WhisperGate was deployed in Ukraine as a destructive attack targeting selected organizations rather than a self-spreading worm. One reported intrusion vector was a compromise of a technology service provider used to access customer environments.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
25 references tracked. Mallory keeps watching after this page renders.
trellix.com
Open sourcetrellix.com
Open sourcemaxkersten.nl
Open sourcesecureworks.com
Open sourcesymantec-enterprise-blogs.security.com
Open sourcezscaler.com
Open sourcewelivesecurity.com
Open sourcecert.gov.ua
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.