WhisperGate is a destructive Windows wiper that masquerades as ransomware and was first observed in January 2022 in attacks against Ukrainian organizations. It is associated with the cyber operations that accompanied the lead-up to Russia’s invasion of Ukraine and has been publicly linked to activity tracked by Microsoft as DEV-0586; U.S. authorities later alleged GRU involvement in the campaign. The malware was used against government and other organizations in Ukraine as part of a broader disruptive effort that also included website defacements and data theft claims intended to intimidate victims and undermine trust in public institutions.
WhisperGate is composed of multiple stages centered on destruction rather than monetization. One component overwrites the master boot record and presents a ransom-style message after reboot, while another component functions as a file wiper that corrupts targeted files on local and remote or mounted drives, including network-accessible logical drives. The file-wiping logic overwrites file content rather than encrypting it, making recovery through ransom payment impossible. Reporting also describes a beaconing or loader stage that retrieves an additional in-memory payload and uses legitimate Windows utilities to execute the final destructive component.
Observed tradecraft includes use of PowerShell and VBScript for execution and defense evasion, attempts to disable or impair Microsoft Defender, exclusion of the system drive from Defender scanning, recognition of monitoring or security tools on the host, enumeration of connected remote logical drives, and process hollowing or injection into a suspended legitimate process to run the final payload. Some analyses also noted use of a .NET loader and a packed payload delivery chain, with the loader downloading and unpacking an additional stage before launching the wiper in memory.
WhisperGate was deliberately deployed to selected targets rather than operating as a self-propagating worm. Reported intrusion vectors around the January 2022 incidents included compromise of a service provider or website management infrastructure and possible exploitation of internet-facing systems associated with affected Ukrainian entities, but the malware itself is best characterized as a targeted destructive payload used post-compromise. Its operational purpose was sabotage and disruption, not extortion, despite its ransomware-themed presentation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Cyberattack using WhisperGate... WhisperGate: This malware downloads and executes additional payload from the C&C server constructed on Discord.
7 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Microsoft warned of destructive data-wiping malware disguised as ransomware being used in attacks against multiple organizations in Ukraine. The company, which is calling this new malware family WhisperGate, attributed it to a threat cluster it's tracking as DEV-0586.
The Conspirators infected computers on these and other networks with malware called WhisperGate, which was designed to look like ransomware. However, as the indictment alleges, WhisperGate was actually a cyberweapon designed to completely destroy the target computer and related data.
Today, the UK and allies can confirm that it was Unit 29155 specifically that was responsible for deploying the Whispergate malware against multiple victims across Ukraine prior to Russia’s invasion in 2022.
The group is also known to have performed the WhisperGate disruptive attack against the Ukrainian government entities in early 2022.
Starting on January 13th, 2022, several Ukrainian organizations were hit with a destructive malware now known as WhisperGate.
Sandworm (GRU Unit 74455) известен деструктивными атаками ... и вайпером WhisperGate.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
reports from several entities, including the Ukrainian CERT, provide enough context to identify general behaviors and techniques used by the adversary: Use of compromised credentials to access victim environments via single-factor authentication | Use of compromised credentials to access victim environments via single-factor authentication
The content repeatedly describes threat actors and malware using PowerShell to execute payloads, run commands, download additional malware, perform lateral movement, evade defenses, and execute scripts in memory. | Examples include: 'APT28 downloads and executes PowerShell scripts and performs PowerShell commands'; 'APT3 has used PowerShell on victim systems to download and run payloads after exploitation'; 'TA505 has used PowerShell to download and execute malware and reconnaissance scripts.'
reports from several entities, including the Ukrainian CERT, provide enough context to identify general behaviors and techniques used by the adversary: Use of compromised credentials to access victim environments via single-factor authentication | Use of compromised credentials to access victim environments via single-factor authentication
This file is used to create the host process where the final wiper payload is injected, using a technique known as process hollowing.
Agent Tesla has used process hollowing to create and manipulate processes through sections of unmapped memory by reallocating that space with its malicious code. APT-C-36 has used process hollowing to execute malware in the memory of legitimate processes. Astaroth can create a new process in a suspended state from a targeted legitimate process in order to unmap its memory and replace it with malicious code.
reports from several entities, including the Ukrainian CERT, provide enough context to identify general behaviors and techniques used by the adversary: Use of compromised credentials to access victim environments via single-factor authentication | Use of compromised credentials to access victim environments via single-factor authentication
The file byte order is reversed, likely to evade detection by host-based controls. The loader restores the byte order and then performs multiple rounds of extraction and decoding of nested resources to get to the final malicious code.
Although the payload's filename suggests that it is a JPG image file, it is a DLL file.
This file is used to create the host process where the final wiper payload is injected, using a technique known as process hollowing.
Agent Tesla has used process hollowing to create and manipulate processes through sections of unmapped memory by reallocating that space with its malicious code. APT-C-36 has used process hollowing to execute malware in the memory of legitimate processes. Astaroth can create a new process in a suspended state from a targeted legitimate process in order to unmap its memory and replace it with malicious code.
The code also included a function that runs a command (cmd.exe /min /C ping 111.111.111.111 -n 5 -w 10 > Nul & Del /f /q "%s") that uses ping to inject a brief time delay before deleting a file.
reports from several entities, including the Ukrainian CERT, provide enough context to identify general behaviors and techniques used by the adversary: Use of compromised credentials to access victim environments via single-factor authentication | Use of compromised credentials to access victim environments via single-factor authentication
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
Examples include: "Babuk can enumerate disk volumes," "Confucius has used a file stealer that can examine system drives," and "XAgentOSX contains the getInstalledAPP function to run ls -la /Applications to gather what applications are installed."
APT1 listed connected network shares. APT32 used the net view command to show all shares available, including the administrative shares such as C$ and ADMIN$. APT41 used the net share command as part of network reconnaissance.
Another example is the case of HermeticWiper. As part of its activity, the malware drops one of several drivers to support its wiper actions.
the attack is believed to have been carried out after the malicious actors gained access to the infrastructure of a private company that had the rights to manage some of the affected websites. Separately, Microsoft warned of destructive data-wiping malware disguised as ransomware being used in attacks against multiple organizations in Ukraine.
When both the website defacements and the first WhisperGate malware deployments occurred in mid-January, we were contacted by three Ukrainian government agencies we have worked with in the past.
29 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
148 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Disruptive wiper malware associated in the article with the same threat actor's earlier attacks on Ukrainian government entities.
Destructive malware used to deface and disrupt Ukrainian government systems ahead of Russia's 2022 invasion.
Wiper malware intended to delete data from infected systems; attributed here to GRU unit 29155 and noted as having hit Ukraine in 2022.
Wiper malware referenced as part of destructive Sandworm operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.