EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Technical advisory

New data wiper malware used in Ukraine

Verified open source
Intelligence with traceable provenance. EudorIA retains technical indicators acquired from supported feeds, with source, date and context. Shareable IOCs are available in the STIX feeds; detection and blocking actions require an assessment of validity, confidence and applicability to the customer's environment. Browse STIX feeds
EudorIA operational summary

What it means

Priority 70/100

MISP EudorIA ha pubblicato l'advisory "New data wiper malware used in Ukraine". Occorre verificarne l'applicabilita rispetto a prodotti e servizi in uso.

Why it matters

Un advisory attendibile puo richiedere verifiche, aggiornamenti o mitigazioni, ma l'applicabilita va confermata sul perimetro reale.

AudienceITSOCCISO

Text acquired from the source

Evento MISP pubblicato con TLP:CLEAR: New data wiper malware used in Ukraine. Report from - [URL rimossa] (1645824136) html [if IE 8 ]> **WMI query format:** > > *SELECT * FROM Win32\_PingStatus WHERE Address={configured\_c2\_domain}* > > **3.** Sends a network request to download the next stage payload using the IP address obtained from step #2 and also exfiltrate the information collected from step #1 using the UserAgent field > **UserAgent Format:** > > {hardcoded\_useragent\_string}**::**%USERPROFILE%**\_**%SYSTEMDRIVE%.SerialNumber**::\.**{static\_string}**\.** > > **4.** Drops and executes the downloaded payload **Note:** At the time of analysis we didn’t get this next stage payload but based on past analysis the threat actor is known to drop some remote desktop application like UltraVNC **Attack Chain #2** We identified another attack-chain used by the same threat actor which is not documented anywhere in the public domain, to the best of our knowledge. Based on our research, this campaign has been active since as early as November 2020 and only 7 unique samples have been identified till date related to this campaign. The most recent instance was observed on 11th Feb 2022 and based on the filename, we believe that it was distributed on 8th Feb 2022 to the targeted victim(s). This low-volume campaign involves RAR archive files distributed through spear phishing emails. These RAR archive files contain a malicious Windows shortcut file (LNK) which do

Source
MISP EudorIA
Publishing entity
MISP EudorIA
Entity type
Intelligence community
Area
Global
Original language
it · translation not needed
Publication
30/07/2026 02:46
Sharing
TLP:CLEAR
Indicators reported by the source
43
IOCs indexed for lookup
0 values within the retention period
IOCs available in the STIX feed
33Last sharing verification: 2026-09-26T10:01:13.915026+00:00
MISP event
56cb2bd3-5525-46bd-a454-ea895a5b4d0d
MITRE ATT&CK
Data Destruction - T1485, Disk Structure Wipe - T1561.002, Group Policy Modification - T1484.001, Inhibit System Recovery - T1490, Signed Binary Proxy Execution - T1218
Classification
High
Open the original source