FoxBlade is Microsoft's designation for destructive malware associated with HermeticWiper, used against Windows systems in attacks targeting Ukraine. Identified on February 23, 2022, immediately before Russia's full-scale invasion, it destroys data to disrupt affected systems and organizational operations rather than enable ransom-based recovery. The initial attacks affected hundreds of systems belonging to government, IT, financial, and energy organizations predominantly located in or connected to Ukraine.
FoxBlade has been deployed by the Russian military intelligence-linked threat actor IRIDIUM, also known as Sandworm and Seashell Blizzard. Subsequent operations used FoxBlade alongside CaddyWiper against Ukrainian organizations involved in power generation, water supply, and transportation. Its deployment forms part of a sustained campaign of destructive cyberattacks against Ukrainian government and critical infrastructure networks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Microsoft observed that IRIDIUM deployed Caddywiper and FoxBlade wiper malware to destroy data from networks of organizations involved in power generation, water supply and the transportation of people and goods.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
Microsoft’s Threat Intelligence Center (MSTIC) detected a new round of offensive and destructive cyberattacks directed against Ukraine’s digital infrastructure. We immediately advised the Ukrainian government about the situation, including our identification of the use of a new malware package (which we denominated FoxBlade)
All this builds on our work in recent weeks and months to address escalating cyber activity against Ukrainian targets, including new forms of destructive malware that we previously have discussed publicly.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Destructive malware used in attacks attributed to Seashell Blizzard.
Telsy - DriveSlayer, FoxBlade, KillDisk.NCV, BabaDeda and LorecCPL downloaders used to run Outsteel against Ukraine.
A wiper malware used by IRIDIUM in destructive attacks against Ukrainian critical infrastructure-related organizations.
Destructive wiper malware used in the opening hours of Russia’s 2022 invasion of Ukraine, intended to damage/erase software and data on targeted Ukrainian systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.