New HermeticWiper Malware Destroys Data on Ukrainian Computer Networks

A destructive data-wiping malware known as HermeticWiper is currently compromising hundreds of computers in Ukraine just hours after a major wave of DDoS attacks.

A new data-wiping malware called HermeticWiper is actively targeting organizations in Ukraine, compromising hundreds of computers across the country. ESET Research detects this destructive threat as Win32/KillDisk.NCV and notes that the attack occurs just hours after a series of distributed denial-of-service (DDoS) attacks knock several important Ukrainian websites offline.

The malicious software corrupts data by abusing legitimate drivers from the popular EaseUS Partition Master disk management tool. The threat actors also use a genuine code-signing certificate issued to a Cyprus-based company named Hermetica Digital Ltd., which directly inspires the malware's name.

Analysis of the wiper's file timestamp reveals that attackers compile the code on December 28th, 2021, suggesting that this destructive campaign is in the works for quite some time. Evidence also indicates that in at least one case, the threat actors already have access to the victim's network before they unleash the devastating wiper.

Read More at the original source →