WhisperGate is a multistage destructive wiper targeting Windows systems that masquerades as ransomware. It was deployed against Ukrainian government agencies, nonprofit organizations, and information technology providers in January 2022, before Russia’s full-scale invasion of Ukraine. The campaign was initially tracked by Microsoft as DEV-0586 and subsequently associated with Cadet Blizzard, a Russian military intelligence threat actor linked to GRU Unit 29155.
WhisperGate overwrites the Master Boot Record with a fraudulent ransom note and deploys a separate file-corruption payload downloaded through legitimate Discord infrastructure. The payload overwrites files with selected extensions using repeated corruption bytes and assigns randomized extensions. Its destructive activity affects local disks, attached USB storage, and mounted network shares, rendering systems unbootable and data unusable rather than providing a genuine recovery mechanism.
The malware uses Windows command-shell and encoded PowerShell commands during execution. Its evasion techniques include disguising malicious executables as JPEG images, adding broad Microsoft Defender exclusions through Visual Basic scripting, and injecting a later-stage payload into a suspended process created by a legitimate Windows installation utility. It can use AdvancedRun to execute commands in the Windows TrustedInstaller security context and enumerate connected remote logical drives. The initial-access mechanism for the January 2022 deployment has not been established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Cyberattack using WhisperGate... WhisperGate: This malware downloads and executes additional payload from the C&C server constructed on Discord.
8 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
WhisperGate is a two-stage wiper malware that masquerades as ransomware.
Vladislav Yevgenyevich Borovkov ... officier GRU affecté à l’Unité militaire 29155 ... associé à la campagne WhisperGate.
Recent cyber activity attributed to Russian State actors includes website defacement and wiper malware (WhisperGate) attacks.
The Conspirators infected computers on these and other networks with malware called WhisperGate, which was designed to look like ransomware. However, as the indictment alleges, WhisperGate was actually a cyberweapon designed to completely destroy the target computer and related data.
The group is also known to have performed the WhisperGate disruptive attack against the Ukrainian government entities in early 2022.
Starting on January 13th, 2022, several Ukrainian organizations were hit with a destructive malware now known as WhisperGate.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
30 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
163 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a historical example associated with a broad Microsoft Defender exclusion of the C: drive.
Destructive wiper mentioned as targeting Ukrainian government and private-sector networks and linked in public attribution statements to AcidRain.
Malware/campaign referenced only in connection with GRU officer Vladislav Borovkov and Unit 29155; no technical behavior is described in the content.
Disruptive wiper malware associated in the article with the same threat actor's earlier attacks on Ukrainian government entities.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.