ATT&CKSoftwareWhisperGate

WhisperGate

S0689

Malware.View on attack.mitre.org

About this malware

WhisperGate is a multi-stage wiper designed to look like ransomware that has been used against multiple government, non-profit, and information technology organizations in Ukraine since at least January 2022.

Techniques used28

Procedure examples28

TechniqueProcedure example
T1027.013
Encrypted/Encoded File

WhisperGate can Base64 encode strings, store downloaded files in reverse byte order, and use the Eazfuscator tool to obfuscate its third stage.

T1036
Masquerading

WhisperGate has been disguised as a JPG extension to avoid detection as a malicious PE file.

T1055.012
Process Hollowing

WhisperGate has the ability to inject its fourth stage into a suspended process created by the legitimate Windows utility `InstallUtil.exe`.

T1059.001
PowerShell

WhisperGate can use PowerShell to support multiple actions including execution and defense evasion.

T1059.003
Windows Command Shell

WhisperGate can use `cmd.exe` to execute commands.

T1059.005
Visual Basic

WhisperGate can use a Visual Basic script to exclude the `C:\` drive from Windows Defender.

T1070.004
File Deletion

WhisperGate can delete tools from a compromised host after execution.

T1071.001
Web Protocols

WhisperGate can make an HTTPS connection to download additional files.

T1083
File and Directory Discovery

WhisperGate can locate files based on hardcoded file extensions.

T1102
Web Service

WhisperGate can download additional payloads hosted on a Discord channel.

T1105
Ingress Tool Transfer

WhisperGate can download additional stages of malware from a Discord CDN channel.

T1106
Native API

WhisperGate has used the `ExitWindowsEx` to flush file buffers to disk and stop running processes and other API calls.

T1134.002
Create Process with Token

The WhisperGate third stage can use the AdvancedRun.exe tool to execute commands in the context of the Windows TrustedInstaller group via `%TEMP%\AdvancedRun.exe" /EXEFilename "C:\Windows\System32\sc.exe" /WindowState 0 /CommandLine "stop WinDefend" /StartDirectory "" /RunAs 8 /Run`.

T1135
Network Share Discovery

WhisperGate can enumerate connected remote logical drives.

T1140
Deobfuscate/Decode Files or Information

WhisperGate can deobfuscate downloaded files stored in reverse byte order and decrypt embedded resources using multiple XOR operations.

View all 28 procedure examples

Groups that use it1

Campaigns0

None recorded.

References3

  1. Cybereason WhisperGate February 2022 Open source
    Cybereason Nocturnus. (2022, February 15). Cybereason vs. WhisperGate and HermeticWiper. Retrieved March 10, 2022.
  2. Microsoft WhisperGate January 2022 Open source
    MSTIC. (2022, January 15). Destructive malware targeting Ukrainian organizations. Retrieved March 10, 2022.
  3. Unit 42 WhisperGate January 2022 Open source
    Falcone, R. et al.. (2022, January 20). Threat Brief: Ongoing Russia and Ukraine Cyber Conflict. Retrieved March 10, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.