HermeticWiper Malware Devastates Ukrainian Systems Through Boot Records
A newly discovered destructive malware known as HermeticWiper targets Ukrainian organizations by corrupting master boot records to cause complete system failure. The attackers use a fraudulently signed driver to execute the damage while deploying a fake ransomware decoy.
Security researchers uncover a destructive malware strain called HermeticWiper that actively targets Ukrainian organizations. The attackers use a digitally signed driver, fraudulently issued under the shell company name Hermetica Digital Ltd, to deploy the wiper onto Windows devices. This malicious driver grants the malware the deep system access it needs to manipulate the master boot record (MBR) and render the machine completely inoperable.
The malware relies on a custom-written 114KB application that abuses a benign partition management driver to gain direct access to the file system from userland. This destructive technique mirrors past strategies used by notorious threat groups like Lazarus and APT33. By bypassing standard Windows controls through this driver abuse, the wiper securely overwrites critical disk structures without triggering typical operating system safeguards.
Alongside the primary destructive payload, the attackers deploy a decoy ransomware program known as PartyTicket to mask the true purpose of the operation and confuse incident responders. SentinelOne confirms that its customers receive automatic protection against this threat without requiring any additional action. Cybersecurity professionals continue to share indicators of compromise as the rapidly evolving situation in Ukraine unfolds.