Security researchers reported that RuRansom is a destructive malware strain aimed at systems geolocated in Russia, presenting itself as ransomware while functioning primarily as a wiper. The malware checks a victim’s public IP address through external services and exits unless the host appears to be in Russia, then seeks elevated privileges, scans local, removable, and network drives, deletes .bak backup files, and encrypts files with AES/AES-CBC while appending the .fs_invade extension. It also drops a Russian-language note stating there is no decryption or payment path, underscoring that the operation is intended to damage Russian victims rather than extort them.
Researchers said the malware is a .NET 32-bit PE sample that can spread in worm-like fashion across connected systems and USB devices, including by copying itself as Россия-Украина_Война-Обновление.doc.exe. Trend Micro linked RuRansom to the developer behind dnWipe and a downloader for XMRig, suggesting an actor experimenting with multiple destructive and financially motivated tools, while noting attribution remains unconfirmed. VMware and Cyble also described multiple variants that attempt privilege escalation and appear to have been developed during the Russia-Ukraine cyber conflict, with encrypted files considered effectively irreversible.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
VMware published a technical analysis of RuRansom describing its targeting of Russian systems, use of geolocation checks, propagation to removable and network drives, deletion of backup files, AES-based encryption, and politically motivated destructive ransom note. The report also released MITRE ATT&CK mappings, a YARA rule, and file hashes as indicators of compromise.
Cyble Research Labs published an analysis of RURansom as a wiper-ransomware hybrid observed attacking targets in Russia, detailing its Russia-only geolocation check, privilege escalation, worm-like spread, AES-CBC encryption, and deletion of .bak files. The report also noted similarities with dnWiper and cited Trend Micro's view that the same threat actors may be behind both.
Trend Micro reported that RURansom was targeting Russia, assessed it as wiper-like rather than true ransomware, and linked dnWipe and an XMRig downloader to the same developer. The researchers also said they had not identified any victims at the time and believed the malware was still under development.
RuRansom's ransom note says the malware author created RU_Ransom to harm Russia after Vladimir Putin declared war on Ukraine on February 24. This date is explicitly referenced in the malware's embedded message as the motivation for the attack.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 49 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
blogs.vmware.com
Open sourceblog.cyble.com
Open sourcetrendmicro.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.