Newly identified wiper malware 'PathWiper' targets critical infrastructure in Ukraine
June 5, 2025, 5:16 p.m.
Description
A destructive attack on Ukrainian critical infrastructure using a new wiper malware called 'PathWiper' has been observed. The attack, attributed to a Russia-nexus APT group, utilized a legitimate endpoint administration framework to deploy the wiper across connected endpoints. PathWiper overwrites file system artifacts with random data, targeting physical drives, volumes, and network shared drives. Its capabilities are similar to HermeticWiper, previously used against Ukrainian entities. The malware's sophisticated approach to identifying and corrupting connected drives and volumes distinguishes it from earlier wipers. This attack underscores the ongoing threat to Ukrainian infrastructure despite the prolonged conflict with Russia.
Tags
Date
- Created: June 5, 2025, 3:35 p.m.
- Published: June 5, 2025, 3:35 p.m.
- Modified: June 5, 2025, 5:16 p.m.
Indicators
- 7c792a2b005b240d30a6e22ef98b991744856f9ab55c74df220f32fe0d00b6b3
Additional Informations
- Energy
- Government
- Ukraine