CaddyWiper is destructive Windows malware first observed by ESET on March 14, 2022, in attacks against Ukrainian organizations during Russia’s invasion of Ukraine. It has been deployed by Russian state-linked threat actors, including Sandworm, also known as IRIDIUM and associated with Russia’s military intelligence service, the GRU. Targets have included organizations involved in electricity generation, water supply, and transportation. CaddyWiper also accompanied the April 2022 Industroyer2 operation against a Ukrainian energy provider.
Implemented as a 32-bit C++ executable, CaddyWiper destroys user data and partition information on attached drives. It recursively enumerates files, takes ownership and changes permissions to enable destructive access, and overwrites the first 10 MiB of targeted files with zeros. It also modifies physical-drive partition layouts, targeting both Master Boot Record and GUID Partition Table information. Before wiping, it checks whether the host is a domain controller and exits if it is, leaving those systems intact. The malware uses stack strings to obscure strings and hinder static analysis.
CaddyWiper has been deployed through Active Directory Group Policy Objects after attackers had already gained control of victim networks. Its destructive role is operational disruption rather than financial extortion. Despite appearing alongside other Ukraine-targeting wipers, it does not share significant code similarity with HermeticWiper or IsaacWiper.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
CaddyWiper was probably set to hinder recovery processes.
2022-03-15 ⋅ ESET Research ⋅ CaddyWiper: New wiper malware discovered in Ukraine
Slovak cybersecurity company ESET dubbed the third wiper "CaddyWiper," which it said it first observed on March 14 around 9:38 a.m. UTC.
Notable attacks included the deployment of Industroyer2 against energy facilities and widespread use of CaddyWiper malware.
"CADDYWIPER is a wiper that Mandiant first identified and reported on in March 2022... The malware enumerates the file system's physical drives and overwrites both file content and partitions with null bytes."
"CADDYWIPER is a wiper that Mandiant first identified and reported on in March 2022... The malware enumerates the file system's physical drives and overwrites both file content and partitions with null bytes."
17 distinct techniques documented for this family, organized by ATT&CK tactic.
To obfuscate strings, one can create a string on the stack, character for character, or in small groups of characters. The concatenation of these characters lead to the existence of the complete string on the stack.
The wiper enumerates through the files, takes ownership of the files overrides File Permissions with SeTakeOwnershipPrivilege and AdjustTokenPrivileges APIs and overwrites 10485760 bytes of data with zeroes.
The wiper checks if the infected machine is a Domain Controller via the DsRoleGetPrimaryDomainInformation API.
The content includes environment-aware checks such as "Bazar can also check if the Russian language is installed on the infected machine and terminate if it is found," "CaddyWiper can also halt execution if the compromised host is identified as a domain controller," and "OopsIE checks for information on the CPU fan, temperature, mouse, hard disk, and motherboard as part of its anti-VM checks."
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, enumerating PIDs, checking for specific process names, or using APIs such as CreateToolhelp32Snapshot and commands such as tasklist and ps.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
If the infected machine is not a Domain Controller, the malware recursively wipes the files in C:\Users and D:\ directories. Additionally, CaddyWiper attempts to wipe the files in the driver letters alphabetically starting from D:\ drive until it reaches Z:\ drive.
"CaddyWiper will also attempt to wipe any network mapped drive attached to the system."
CaddyWiper being deployed via GPO, a circumstance that suggests the attackers had initially compromised the target’s Active Directory server.
The wiper checks if the infected machine is a Domain Controller via the DsRoleGetPrimaryDomainInformation API.
The content includes environment-aware checks such as "Bazar can also check if the Russian language is installed on the infected machine and terminate if it is found," "CaddyWiper can also halt execution if the compromised host is identified as a domain controller," and "OopsIE checks for information on the CPU fan, temperature, mouse, hard disk, and motherboard as part of its anti-VM checks."
Many entries concern “CaddyWiper”, “new data wiper hits Ukraine”, “destructive wiper malware”, and Sandworm operations using CADDYWIPER alongside INDUSTROYER2.
The adversary uses a legitimate code signing certificate to sign the malware binary and abuses a legitimate driver to corrupt data.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
69 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Destructive data wiper deployed against Ukrainian organizations and sometimes used alongside INDUSTROYER2.
Destructive wiper malware previously deployed in attacks tied to Ukrainian blackouts.
Wiper deployed in the IT environment alongside Sandworm OT disruption activity in Ukraine.
A destructive wiper used in two closely related versions; both overwrite targeted files, with the article noting zeroing of the first 10 megabytes of targeted files.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.