Malware & Threats

Destructive ‘PathWiper’ Targeting Ukraine’s Critical Infrastructure

A Russia-linked threat actor has used the destructive malware dubbed PathWiper against a critical infrastructure organization in Ukraine.

Russia attack on Ukraine

Russian threat actors are once again targeting Ukraine’s critical infrastructure with destructive malware, a fresh report from Cisco Talos shows.

Wiper attacks against Ukraine were executed in January and February 2022, in coordination with Russia’s assault on the country, with malware such as WhisperGate, HermeticWiper, IsaacWiper and CaddyWiper identified and analyzed. In April, Industroyer2 was used against industrial control systems (ICS).

As Russia intensified its activities in cyberspace, the attacks continued and Ukraine’s largest mobile network operator, Kyivstar, had its IT infrastructure partially destroyed in a December 2023 cyberattack.

Now, Talos says a critical infrastructure entity within Ukraine fell victim to a destructive attack in which new malware, dubbed PathWiper, was used.

The new malware shares similarities with HermeticWiper, which has been attributed to Sandworm, also tracked as Seashell Blizzard, APT44, Iridium, TeleBots, and Voodoo Bear, an APT group associated with GRU, Russia’s military intelligence.

Both wipers, Talos explains, target the master boot record (MBR) and NTFS-related artifacts for corruption, albeit the mechanisms differ. PathWiper seeks all connected drives and volumes, identifies volume labels, and documents valid records, while HermeticWiper simply enumerates physical drives from 0 to 100.

Advertisement. Scroll to continue reading.

As part of the PathWiper attack, a legitimate endpoint administration framework was used to execute malicious commands and deploy the wiper. The attackers used filenames and actions mimicking those of the utility’s console.

“Any commands issued by the administrative tool’s console were received by its client running on the endpoints. The client then executed the command as a batch (BAT) file, with the command line partially resembling that of Impacket command executions, though such commands do not necessarily indicate the presence of Impacket in an environment,” Talos explains.

When executed, PathWiper attempted to dismount volumes and to replace the contents of file system artifacts with random data, using one thread per drive and volume for each identified path. Targeted artifacts include MBR, $MFT, $MFTMirr, $LogFile, $Boot, $Bitmap, $TxfLog, $Tops, and $AttrDef.

Some of the 2022 wiper attacks against Ukraine were attributed to Cadet Blizzard, an APT operating on behalf of GRU. Last year, the US announced charges against a member of the group.

Related: Kapeka: A New Backdoor in Sandworm’s Arsenal of Aggression

Related: Andrei Tarasov: Inside the Journey of a Russian Hacker on the FBI’s Most Wanted List

Related: Recorded Future Tagged as ‘Undesirable’ in Russia

Related: Google Details Recent Ukraine Cyberattacks

Related Content

Malware & Threats

The malware-as-a-service operation launches legitimate browsers on an invisible desktop, giving attackers persistent and covert remote access to compromised Windows systems.

Artificial Intelligence

SentinelOne’s new benchmark, built on the Fast16 case, shows which AI models can sustain a malware investigation and which cannot.

Malware & Threats

Part of a larger toolkit, HollowGraph uses a compromised 365 account’s calendar as a two-way dead-drop.

Malware & Threats

The zero-days CVE-2026-15409 and CVE-2026-15410 were exploited by a threat actor tracked by Volexity as UTA0533.

Malware & Threats

The new macOS malware has targeted at least 100 users to steal their passwords and cryptocurrency. 

Endpoint Security

Bitdefender researchers show how Windows bind links can create conflicting filesystem views to hide malware from endpoint security products.

Cybercrime

The suspects and their companies were previously sanctioned by the United States and its allies.

Government

Multiple state-sponsored APTs are compromising poorly secured devices across critical infrastructure sector networks.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version