IsaacWiper is a destructive Windows malware family written in C++ and used against Ukrainian organizations, including government entities, during Russia’s invasion of Ukraine. It was observed in attacks on February 24, 2022. CERT-UA has associated the malware with the intrusion cluster UAC-0082. Its purpose is to destroy data and disrupt operations rather than encrypt files for recoverable ransom-based extortion.
IsaacWiper enumerates physical drives and logical volumes, obtains disk geometry and available-space information, and attempts to lock volumes before overwriting their contents. It overwrites the first 1 MiB of physical drives before proceeding with broader drive and file destruction. Overwrite data is generated using a Mersenne Twister pseudorandom number generator. If a file cannot be opened, the malware attempts to rename it to a temporary name. When direct volume access fails, it creates hidden temporary directories and fills temporary files with pseudorandom data until the volume has no free space remaining. Analyzed variants also record diagnostic information about their wiping activity.
IsaacWiper is distinct from CaddyWiper, with no significant code similarity established between the families. Its shared use of Mersenne Twister with CryWiper does not establish a substantive code or operational relationship.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
IsaacWiper: ... Cyberattacks against Ukrainian government organizations on February 24, 2022.
In 2022, the Russian APT used multiple wipers in attacks aimed at Ukraine, including AwfulShred, CaddyWiper, HermeticWiper, Industroyer2, IsaacWiper, WhisperGate, Prestige, RansomBoggs, and ZeroWipe.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
Following the creation of the log file, the wiper enumerates all physical drives on the target system... IsaacWiper checks the resulting physical drive list... With a list of disk objects, IsaacWiper leverages IOCTL_DISK_GET_DRIVE_GEOMETRY_EX and GetDiskFreeSpaceExW() to obtain the size and available free space of each disk.
The resources below detail destructive malware used to destroy an organization’s critical assets and data.
The malware was designed to wipe the Master Boot Record, MBR, and proceed to corrupt the files on disk, destroying all traces of the data.
Many wipers also make sure to overwrite the Master Boot Record (MBR) of the disk.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
36 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Wiper malware targeting Ukrainian government networks during the pre-invasion cyber campaign.
Mentioned in a list of wipers observed after AcidRain.
A wiper malware referenced in the dataset generation context for Windows, associated here with DLL RawDiskRead activity.
Destructive wiper used in attacks (noted in 2022 activity).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.