New HermeticWiper Malware Destroys Data Across Ukraine Networks

A destructive data-wiping malware called HermeticWiper is currently compromising hundreds of computers in Ukraine. The attackers use ransomware as a decoy to distract victims while the malware permanently destroys their data.

A new data-wiping malware known as HermeticWiper is actively compromising hundreds of computers in Ukraine. The attacks emerge just hours after a wave of distributed denial-of-service (DDoS) attacks targets various Ukrainian government websites, escalating the ongoing cyber conflict in the region.

The malware abuses legitimate EaseUS Partition Master software drivers to corrupt and destroy data on infected machines. Its name comes from a code-signing certificate issued to Hermetica Digital Ltd., a shell company based in Cyprus that the attackers registered just last year to lend false legitimacy to their operations.

Security researchers note that HermeticWiper uses ransomware as a decoy to distract victims from the actual data destruction, mirroring the tactics of the WhisperGate malware from January. Evidence suggests the threat actors infiltrate target networks months in advance, with one Lithuanian organization showing signs of compromise dating back to November.

Read More at the original source →