On February 23, 2022, the ESET threat research team disclosed findings pertaining to a Data Wiper malware campaign impacting hundreds of systems across Ukraine, named HERMETICWIPER.
HermeticWiper
HermeticWiper, also tracked as DriveSlayer and Trojan.Killdisk, is destructive Windows malware designed to corrupt disk structures and file data, rendering systems inoperable.
HermeticWiper
Family profile
HermeticWiper, also tracked as DriveSlayer and Trojan.Killdisk, is destructive Windows malware designed to corrupt disk structures and file data, rendering systems inoperable. First observed on February 23, 2022, it affected hundreds of computers at Ukrainian organizations immediately before Russia’s full-scale invasion. Targets included government, financial, defense, aviation, and IT services organizations. CERT-UA associated its use with the intrusion cluster UAC-0082.
The malware embeds four compressed, legitimate EaseUS Partition Master drivers and selects one according to the Windows version and architecture. It installs the selected driver as a kernel-mode service and abuses its low-level disk-access functionality to bypass normal operating-system protections. Its multithreaded wiping routines overwrite master boot records, partition and filesystem structures, and file data with random bytes. It handles FAT and NTFS volumes, including corruption of NTFS metadata, and targets recovery data and event logs. HermeticWiper disables crash-dump generation and the Volume Shadow Copy service, hindering forensic analysis and recovery, then forces a shutdown or reboot that leaves affected machines unable to boot. Identified binaries were digitally signed with a certificate issued to Hermetica Digital Ltd., which inspired the malware’s name.
Attackers deployed HermeticWiper within compromised Windows networks, including through Active Directory Group Policy and from domain controllers. HermeticWizard assisted its distribution across local networks, while the separate HermeticRansom ransomware accompanied some attacks as a decoy. HermeticWiper itself has no identified built-in network command-and-control or self-propagation mechanism; its primary function is irreversible destruction rather than encryption for extortion.
Capabilities
- Byovd
- Defense Evasion
- Post Exploitation
Samples
Recent samples
3 sandbox samples in the Derp library, newest 3 shown
Reported operators
Threat actors
9 named in public reportingOn February 23, 2022, the ESET threat research team disclosed findings pertaining to a Data Wiper malware campaign impacting hundreds of systems across Ukraine, named HERMETICWIPER.
UAC-0082 (HermeticWiper, IsaacWiper, CaddyWiper)
...cyber offensives targeting Ukraine that resulted in the deployment of a data wiper called HermeticWiper on hundreds of machines in the East European nation.
HermeticWiper is a sophisticated malware family that is designed to destroy data and render a system inoperable.
CaddyWiper is notable for the fact that it doesn't share any similarities with previously discovered wipers in Ukraine, including HermeticWiper (aka FoxBlade or KillDisk) and IsaacWiper (aka Lasainraw).
ESET reported on March 1st that multiple Ukrainian organizations were targeted by an attack campaign comprising: HermeticWiper, a data-wiping malware.
ESET reported on March 1st that multiple Ukrainian organizations were targeted by an attack campaign comprising: HermeticWiper, a data-wiping malware.
PathWiper’s mechanisms are somewhat semantically similar to another wiper family, HermeticWiper, previously seen targeting Ukrainian entities in 2022. HermeticWiper, also known as FoxBlade or NEARMISS, is attributed to Russia’s Sandworm group in third-party reporting.
Exploited software
Vulnerabilities linked to HermeticWiper
1 CVEsMITRE ATT&CK
HermeticWiper in ATT&CK
56 distinct techniquesTechniques
56 techniquesReporting
Research mentioning HermeticWiper
GitHub - tjnel/certgraveyard_yara: Automated YARA rule generation from the Cert Central compromised certificate database. · GitHub
A public project called CertGraveyard has expanded efforts to document abused code-signing certificates used to sign malware, building a shared record of certificate abuse and helping defenders trigger revocations with certificate authorities. The project’s creator said the initiative grew out of years of reporting malicious certificates tied to malware such as SolarMarker, and has helped report more than 2,000 certificates, later growing to roughly 2,400 entries in the database. Supporting tooling includes certReport, which automates abuse reports from malware hashes using sources such as VirusTotal and MalwareBazaar, plus an API, downloadable datasets, feeds, hunting queries, and integrations with platforms including MalwareBazaar, UnpacMe, Malcat, MagicSword.io, and WDAC enforcement workflows. The database reflects a broader pattern in which threat actors repeatedly obtain or abuse valid Authenticode certificates to make malware appear trustworthy, reduce Windows warnings, and sustain delivery campaigns. Prior reporting cited SolarMarker cycling through impostor-issued certificates, FakeBat distributing signed MSI and MSIX installers, Netbounce using valid certificates and fake software branding, Dark Caracal signing Bandook variants with legitimate certificates, and Operation Red Signature abusing a stolen vendor certificate in a supply-chain intrusion. CertGraveyard’s operator said certificate authorities often act on external reports within hours, making revocation a practical disruption measure, though the project has also faced operational pressure including a major DDoS attack while handling heavy daily lookup and download volumes from defenders and malware-analysis integrations.
Incident response statistics and cases at educational institutions in Brazil | Securelist
Brazilian educational institutions faced a sustained wave of cyber incidents in incident-response cases reviewed from January 2025 through June 2026, with attackers most often gaining access through valid accounts, exploitation of public-facing applications, insider activity, and weak patch management. High-severity cases were dominated by ransomware, particularly DragonForce and LockBit 3, and private institutions were more frequently affected than public ones. Investigators also found that outdated and unpatched systems, including Windows 10 deployments kept past end of support and unpatched Windows Server 2016 hosts, materially increased exposure. Representative intrusions showed attackers relying on common but effective techniques rather than novel tradecraft. One LockBit case involved a custom deployment built from the leaked builder and spread with PsExec, aligning with the well-documented abuse of Windows service execution for lateral movement and payload launch. Another DragonForce intrusion used AnyDesk and log wiping to maintain access and hinder response, while a separate insider case involved a Python keylogger installed on a shared machine to capture credentials. The findings underscore the need for MFA, least privilege, removal of shared accounts, tighter control of remote-access tools, stronger backups, centralized logging, longer EDR retention, and faster patching.