Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In an operation with the Ukrainian Cyber Alliance, Hacking Cat deployed Nemo Wiper.
In an operation with the Ukrainian Cyber Alliance, Hacking Cat deployed Nemo Wiper.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Служба меняет HKLM\SYSTEM\CurrentControlSet\Services\USBSTOR\Start на 4, блокируя загрузку USB Mass Storage; скрипт также включает AutoAdminLogon и Safe Mode with Networking.
LSAPlatformUpdate.ps1 создает нового локального пользователя и добавляет его в группу администраторов, затем включает AutoAdminLogon.
Служба меняет HKLM\SYSTEM\CurrentControlSet\Services\USBSTOR\Start на 4, блокируя загрузку USB Mass Storage; скрипт также включает AutoAdminLogon и Safe Mode with Networking.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Destructive malware that overwrites files with random bytes and fills free disk space with randomly named files using the .lock extension.
Destructive wiper used in a June 2026 operation against a heating provider. It erases data and is intended to disrupt critical infrastructure rather than generate ransom payments.
Destructive wiper malware intended to destroy data and disrupt infrastructure rather than obtain ransom payments.
A destructive Windows wiper delivered through a malicious network-provider/DLL persistence chain found alongside Gorilla RAT in a victim environment. It stops services protecting database, virtualization, container, and WSL data; partially overwrites files with random data based on file size; and exhausts free disk space with random files to hinder recovery.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.