HermeticWiper
Also known as: DriveSlayer, FoxBlade, KillDisk.NCV, NEARMISS
According to SentinelLabs, HermeticWiper is a custom-written application with very few standard functions. It abuses a signed driver called "empntdrv.sys" which is associated with the legitimate Software "EaseUS Partition Master Software" to enumerate the MBR and all partitions of all Physical Drives connected to the victims Windows Device and overwrite the first 512 Bytes of every MBR and Partition it can find, rendering them useless.
This malware is associated to the malware attacks against Ukraine during Russians Invasion in February 2022.
Last 7 days
May 14, 2026
C2 Hosts: 1
| Date | C2 Hosts |
|---|---|
| May 14, 2026 | 1 |