HermeticWiper, also tracked as DriveSlayer and Trojan.Killdisk, is destructive Windows malware designed to corrupt disk structures and file data, rendering infected systems unbootable. Discovered on February 23, 2022, immediately before Russia’s invasion of Ukraine, it affected hundreds of Ukrainian computers, with additional infections observed in Latvia and Lithuania. Targeted organizations included government entities and businesses in finance, defense, aviation, and IT services. CERT-UA associated HermeticWiper activity with the UAC-0082 intrusion cluster.
The malware embeds four compressed, legitimate EaseUS Partition Master drivers covering different Windows versions and architectures. It selects and installs an appropriate driver as a kernel-mode service, then abuses its raw disk access to bypass normal operating-system protections. Its destructive routines overwrite master boot records, partition structures, FAT and NTFS filesystem data, and file contents with randomly generated data. It also targets recovery information, disables the Volume Shadow Copy service and crash-dump generation, and shuts down the host so boot-related corruption takes effect. Identified binaries were digitally signed using a certificate associated with Hermetica Digital Ltd., which supplied the malware’s name.
HermeticWiper was deployed within previously compromised networks, including through Active Directory Group Policy. It has no identified built-in network command-and-control or self-propagation mechanism. Separate HermeticRansom ransomware, also known as PartyTicket, was deployed alongside it in some attacks; HermeticWiper itself performs destructive overwriting rather than ransomware encryption and does not display a ransom note.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The attackers appear to have used an exploit of a known vulnerability in Microsoft SQL Server (CVE-2021-1636) in order to compromise at least one of the targeted organisations. The organization was running an unpatched version of Microsoft SQL Server.
9 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
HermeticWiper: Malware that makes a system inoperable by corrupting its data.
On February 23, 2022, the ESET threat research team disclosed findings pertaining to a Data Wiper malware campaign impacting hundreds of systems across Ukraine, named HERMETICWIPER.
On February 23, 2022, the ESET threat research team disclosed findings pertaining to a Data Wiper malware campaign impacting hundreds of systems across Ukraine, named HERMETICWIPER.
...cyber offensives targeting Ukraine that resulted in the deployment of a data wiper called HermeticWiper on hundreds of machines in the East European nation.
HermeticWiper is a sophisticated malware family that is designed to destroy data and render a system inoperable.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
39 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
124 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A 2022 variant mentioned in the family history/updates that is referred to as HermeticWiper and uses legitimate EaseUS Partition Master software to damage disk partitions.
Wiper malware used to destroy or disrupt systems across multiple Ukrainian sectors immediately prior to the 2022 invasion.
Referenced as historical comparison for destructive malware focused on immediate operational impact.
Destructive wiper malware observed in telemetry shortly before the tournament kickoff window.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.