FoxBlade is a malware designation used by Microsoft for activity observed immediately before and during the opening phase of Russia’s 2022 invasion of Ukraine. It has been described as a trojan capable of covertly weaponizing infected Windows systems for distributed denial-of-service activity and of downloading and installing additional programs, including other malware. In reporting on destructive operations against Ukraine, Microsoft also associated the FoxBlade name with HermeticWiper and HermeticWizard-related activity, and some tracking references use FoxBlade as an alternate name in that cluster. The malware has been linked with Russian state operations targeting Ukraine, including activity attributed with medium confidence to IRIDIUM, also widely tracked as Sandworm or Seashell Blizzard, a GRU-linked threat actor.
FoxBlade was used against Ukrainian organizations in the period surrounding the February 2022 invasion and was reported impacting hundreds of systems across government, IT, financial, and energy organizations predominantly located in or tied to Ukraine. Subsequent reporting also placed FoxBlade in destructive campaigns affecting organizations involved in power generation, water supply, and transportation. The broader targeting pattern aligns with Russian disruptive and destructive operations against Ukrainian civilian and critical infrastructure sectors, including energy, transportation, water, emergency services, and other government-linked entities.
At high confidence, FoxBlade supports distributed denial-of-service operations through compromised hosts and can act as a delivery mechanism for follow-on payloads by downloading and installing additional malware. It is therefore best understood as part of a broader offensive toolkit used in coordinated wartime cyber operations rather than as a standalone commodity threat. Public reporting consistently places it in the context of highly targeted attacks against Ukrainian networks rather than indiscriminate global propagation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Microsoft observed that IRIDIUM deployed Caddywiper and FoxBlade wiper malware to destroy data from networks of organizations involved in power generation, water supply and the transportation of people and goods.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
Microsoft’s Threat Intelligence Center (MSTIC) detected a new round of offensive and destructive cyberattacks directed against Ukraine’s digital infrastructure. We immediately advised the Ukrainian government about the situation, including our identification of the use of a new malware package (which we denominated FoxBlade)
All this builds on our work in recent weeks and months to address escalating cyber activity against Ukrainian targets, including new forms of destructive malware that we previously have discussed publicly.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Destructive malware used in attacks attributed to Seashell Blizzard.
A wiper malware used by IRIDIUM in destructive attacks against Ukrainian critical infrastructure-related organizations.
Destructive wiper malware used in the opening hours of Russia’s 2022 invasion of Ukraine, intended to damage/erase software and data on targeted Ukrainian systems.
Trojan that covertly turns victim machines into assets for DDoS attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.