Skip to content

HermeticWiper

HermeticWiper, also tracked as DriveSlayer and Trojan.Killdisk, is destructive Windows malware designed to corrupt disk structures and file data, rendering systems inoperable.

HermeticWiper

Family profile

HermeticWiper, also tracked as DriveSlayer and Trojan.Killdisk, is destructive Windows malware designed to corrupt disk structures and file data, rendering systems inoperable. First observed on February 23, 2022, it affected hundreds of computers at Ukrainian organizations immediately before Russia’s full-scale invasion. Targets included government, financial, defense, aviation, and IT services organizations. CERT-UA associated its use with the intrusion cluster UAC-0082.

The malware embeds four compressed, legitimate EaseUS Partition Master drivers and selects one according to the Windows version and architecture. It installs the selected driver as a kernel-mode service and abuses its low-level disk-access functionality to bypass normal operating-system protections. Its multithreaded wiping routines overwrite master boot records, partition and filesystem structures, and file data with random bytes. It handles FAT and NTFS volumes, including corruption of NTFS metadata, and targets recovery data and event logs. HermeticWiper disables crash-dump generation and the Volume Shadow Copy service, hindering forensic analysis and recovery, then forces a shutdown or reboot that leaves affected machines unable to boot. Identified binaries were digitally signed with a certificate issued to Hermetica Digital Ltd., which inspired the malware’s name.

Attackers deployed HermeticWiper within compromised Windows networks, including through Active Directory Group Policy and from domain controllers. HermeticWizard assisted its distribution across local networks, while the separate HermeticRansom ransomware accompanied some attacks as a decoy. HermeticWiper itself has no identified built-in network command-and-control or self-propagation mechanism; its primary function is irreversible destruction rather than encryption for extortion.

Capabilities

  • Byovd
  • Defense Evasion
  • Post Exploitation

Samples

Recent samples

3 sandbox samples in the Derp library, newest 3 shown

Reported operators

Threat actors

9 named in public reporting
Lazarus

On February 23, 2022, the ESET threat research team disclosed findings pertaining to a Data Wiper malware campaign impacting hundreds of systems across Ukraine, named HERMETICWIPER.

Shamoon

On February 23, 2022, the ESET threat research team disclosed findings pertaining to a Data Wiper malware campaign impacting hundreds of systems across Ukraine, named HERMETICWIPER.

UAC-0082

UAC-0082 (HermeticWiper, IsaacWiper, CaddyWiper)

GRU

...cyber offensives targeting Ukraine that resulted in the deployment of a data wiper called HermeticWiper on hundreds of machines in the East European nation.

Gamaredon Group

HermeticWiper is a sophisticated malware family that is designed to destroy data and render a system inoperable.

DEV-0665

CaddyWiper is notable for the fact that it doesn't share any similarities with previously discovered wipers in Ukraine, including HermeticWiper (aka FoxBlade or KillDisk) and IsaacWiper (aka Lasainraw).

UNC1151

ESET reported on March 1st that multiple Ukrainian organizations were targeted by an attack campaign comprising: HermeticWiper, a data-wiping malware.

Ember Bear

ESET reported on March 1st that multiple Ukrainian organizations were targeted by an attack campaign comprising: HermeticWiper, a data-wiping malware.

Sandworm

PathWiper’s mechanisms are somewhat semantically similar to another wiper family, HermeticWiper, previously seen targeting Ukrainian entities in 2022. HermeticWiper, also known as FoxBlade or NEARMISS, is attributed to Russia’s Sandworm group in third-party reporting.

Exploited software

Vulnerabilities linked to HermeticWiper

1 CVEs

MITRE ATT&CK

HermeticWiper in ATT&CK

56 distinct techniques

Techniques

56 techniques
T1561.002 Disk Structure Wipe T1497.003 Time Based Checks T1106 Native API T1036.005 Match Legitimate Resource Name or Location T1484.001 Group Policy Modification T1134 Access Token Manipulation T1529 System Shutdown/Reboot T1553.002 Code Signing T1083 File and Directory Discovery T1561.001 Disk Content Wipe T1543.003 Windows Service T1685 Disable or Modify Tools T1140 Deobfuscate/Decode Files or Information T1059.003 Windows Command Shell T1070 Indicator Removal T1027.015 Compression T1082 System Information Discovery T1489 Service Stop T1070.004 File Deletion T1490 Inhibit System Recovery T1685.005 Clear Windows Event Logs T1112 Modify Registry T1485 Data Destruction T1053.005 Scheduled Task T1680 Local Storage Discovery T1569.002 Service Execution T1218.005 Mshta T1570 Lateral Tool Transfer T1021.002 SMB/Windows Admin Shares T1047 Windows Management Instrumentation T1003.001 LSASS Memory T1105 Ingress Tool Transfer T1218 System Binary Proxy Execution T1566 Phishing T1561 Disk Wipe T1543 Create or Modify System Process T1548 Abuse Elevation Control Mechanism T1059.001 PowerShell T1053 Scheduled Task/Job T1068 Exploitation for Privilege Escalation T1505.003 Web Shell T1190 Exploit Public-Facing Application T1014 Rootkit T1078 Valid Accounts T1498 Network Denial of Service T1210 Exploitation of Remote Services T1528 Steal Application Access Token T1003 OS Credential Dumping T1499 Endpoint Denial of Service T1560 Archive Collected Data T1036 Masquerading T1497.001 System Checks T1564 Hide Artifacts T1070.009 Clear Persistence T1027 Obfuscated Files or Information T1120 Peripheral Device Discovery

Reporting

Research mentioning HermeticWiper

Aug 15
Github Web

GitHub - tjnel/certgraveyard_yara: Automated YARA rule generation from the Cert Central compromised certificate database. · GitHub

A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.

Aug 3
Securelist

Incident response statistics and cases at educational institutions in Brazil | Securelist

Brazilian educational institutions faced a sustained wave of cyber incidents in incident-response cases reviewed from January 2025 through June 2026, with attackers most often gaining access through valid accounts, exploitation of public-facing applications, insider activity, and weak patch management. High-severity cases were dominated by ransomware, particularly DragonForce and LockBit 3, and private institutions were more frequently affected than public ones. Investigators also found that outdated and unpatched systems, including Windows 10 deployments kept past end of support and unpatched Windows Server 2016 hosts, materially increased exposure. Representative intrusions showed attackers relying on common but effective techniques rather than novel tradecraft. One LockBit case involved a custom deployment built from the leaked builder and spread with PsExec, aligning with the well-documented abuse of Windows service execution for lateral movement and payload launch. Another DragonForce intrusion used AnyDesk and log wiping to maintain access and hinder response, while a separate insider case involved a Python keylogger installed on a shared machine to capture credentials. The findings underscore the need for MFA, least privilege, removal of shared accounts, tighter control of remote-access tools, stronger backups, centralized logging, longer EDR retention, and faster patching.

Jul 28
Sekoia

Exposing FakeBat loader: distribution methods and adversary infrastructure

Jun 23
Github Web

DE-TH-Aura/Defender for Endpoint/ExternalData - Cert Central, CertReport.md at main · SecurityAura/DE-TH-Aura · GitHub

Jun 22
Squiblydoo

Using the Cert Graveyard - Squiblydoo.blog

Apr 1
Squiblydoo

The CertGraveyard - Squiblydoo.blog

Mar 25
Github Web

GitHub - Squiblydoo/certReport: A tool to support the reporting of Authenticode Certificates by reducing the effort on individuals to report. · GitHub

Sep 9
Squiblydoo

Quick abuse reports with certReport - Squiblydoo.blog