ATT&CKSoftwareHermeticWiper

HermeticWiper

S0697

Malware.View on attack.mitre.org

About this malware

HermeticWiper is a data wiper that has been used since at least early 2022, primarily against Ukraine with additional activity observed in Latvia and Lithuania. Some sectors targeted include government, financial, defense, aviation, and IT services.

Techniques used26

Procedure examples26

TechniqueProcedure example
T1027.015
Compression

HermeticWiper can compress 32-bit and 64-bit driver files with the Lempel-Ziv algorithm.

T1036.005
Match Legitimate Resource Name or Location

HermeticWiper has used the name `postgressql.exe` to mask a malicious payload.

T1053.005
Scheduled Task

HermeticWiper has the ability to use scheduled tasks for execution.

T1059.003
Windows Command Shell

HermeticWiper can use `cmd.exe /Q/c move CSIDL_SYSTEM_DRIVE\temp\sys.tmp1 CSIDL_WINDOWS\policydefinitions\postgresql.exe 1> \\127.0.0.1\ADMIN$\_1636727589.6007507 2>&1` to deploy on an infected system.

T1070
Indicator Removal

HermeticWiper can disable pop-up information about folders and desktop items and delete Registry keys to hide malicious services.

T1070.004
File Deletion

HermeticWiper has the ability to overwrite its own file with random bites.

T1082
System Information Discovery

HermeticWiper can determine the OS version and bitness on a targeted host.

T1083
File and Directory Discovery

HermeticWiper can enumerate common folders such as My Documents, Desktop, and AppData.

T1106
Native API

HermeticWiper can call multiple Windows API functions used for privilege escalation, service execution, and to overwrite random bites of data.

T1112
Modify Registry

HermeticWiper has the ability to modify Registry keys to disable crash dumps, colors for compressed files, and pop-up information about folders and desktop items.

T1134
Access Token Manipulation

HermeticWiper can use `AdjustTokenPrivileges` to grant itself privileges for debugging with `SeDebugPrivilege`, creating backups with `SeBackupPrivilege`, loading drivers with `SeLoadDriverPrivilege`, and shutting down a local system with `SeShutdownPrivilege`.

T1140
Deobfuscate/Decode Files or Information

HermeticWiper can decompress and copy driver files using `LZCopy`.

T1484.001
Group Policy Modification

HermeticWiper has the ability to deploy through an infected system's default domain policy.

T1485
Data Destruction

HermeticWiper can recursively wipe folders and files in `Windows`, `Program Files`, `Program Files(x86)`, `PerfLogs`, `Boot, System`, `Volume Information`, and `AppData` folders using `FSCTL_MOVE_FILE`. HermeticWiper can also overwrite symbolic links and big files in `My Documents` and on the Desktop with random bytes.

T1489
Service Stop

HermeticWiper has the ability to stop the Volume Shadow Copy service.

View all 26 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References5

  1. Crowdstrike DriveSlayer February 2022 Open source
    Thomas, W. et al. (2022, February 25). CrowdStrike Falcon Protects from New Wiper Malware Used in Ukraine Cyberattacks. Retrieved March 25, 2022.
  2. ESET Hermetic Wiper February 2022 Open source
    ESET. (2022, February 24). HermeticWiper: New data wiping malware hits Ukraine. Retrieved March 25, 2022.
  3. Qualys Hermetic Wiper March 2022 Open source
    Dani, M. (2022, March 1). Ukrainian Targets Hit by HermeticWiper, New Datawiper Malware. Retrieved March 25, 2022.
  4. SentinelOne Hermetic Wiper February 2022 Open source
    Guerrero-Saade, J. (2022, February 23). HermeticWiper | New Destructive Malware Used In Cyber Attacks on Ukraine. Retrieved March 25, 2022.
  5. Symantec Ukraine Wipers February 2022 Open source
    Symantec Threat Hunter Team. (2022, February 24). Ukraine: Disk-wiping Attacks Precede Russian Invasion. Retrieved March 25, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.