Ukrainian government entities were hit by a coordinated wave of cyber activity that combined website defacements, destructive malware, and phishing operations using compromised or spoofed official email accounts. Cisco Talos said the WhisperGate intrusion chain masqueraded as ransomware but instead overwrote the master boot record and deployed a final-stage wiper, WhisperKill, to destroy files across infected systems while attempting to disable Microsoft Defender. Investigators assessed the attackers likely had access for months using stolen credentials, and Ukrainian officials said the incidents followed a broader pattern of hybrid aggression that had already wiped some government systems and defaced dozens of agency websites.
At the same time, Ukrainian defenders warned of fresh phishing campaigns targeting government institutions with emails impersonating trusted state bodies, including the National Health Service of Ukraine and compromised judiciary accounts. Those messages delivered malware-laced documents hosted on Discord and installed the OutSteel stealer and SaintBot. Talos and Ukrainian authorities said the destructive attacks were intertwined with disinformation activity and possible false-flag efforts designed to shift blame, while formal attribution remained unconfirmed; Ukrainian officials said signs pointed to a Russian APT actor and noted investigative support from partners including the United States and United Kingdom.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
On 2024-06-26, the U.S. Justice Department announced an indictment charging Russian national Amin Timovich Stigal with conspiring with GRU members to deploy WhisperGate against dozens of Ukrainian government entities in January 2022. The indictment also alleged related intrusions, data theft and sale, later targeting of transportation infrastructure in a Central European country, and probing of a U.S. federal agency using the same infrastructure.
On 2022-01-31, Ukrainian cybersecurity officials warned of a new phishing campaign targeting government institutions using compromised or spoofed government email addresses, including messages appearing to come from the National Health Service of Ukraine. The emails delivered Discord-hosted malware-laced documents that deployed the OutSteel stealer and SaintBot.
Two days before the later Monday warning, Ukrainian officials warned that compromised email accounts from the Ukrainian judiciary were being used in a phishing campaign. The messages, disguised as court inquiries, targeted mostly Ukrainian government entities with malware.
On 2022-01-21, Cisco Talos published analysis of the January 2022 attacks, naming the wiper malware WhisperGate and describing its multi-stage infection chain, including a Discord-hosted payload and the WhisperKill file wiper. Talos assessed the attackers likely used stolen credentials and may have maintained access for months before the attack.
On 2022-01-17, the Ukrainian government publicly accused Russia of orchestrating the recent defacements of government and public institution websites, saying the campaign aimed to intimidate society, disrupt the public sector, and undermine trust in government. Ukraine also said the attackers likely accessed the affected sites through the infrastructure of a private company that managed some of them, while Russia denied involvement.
On 2022-01-13, Microsoft first observed the destructive malware later known as WhisperGate targeting multiple organizations in Ukraine. The new reference says Microsoft publicly attributed the malware to the threat actor it tracks as DEV-0586.
In January 2022, dozens of Ukrainian government agency websites were defaced and some government systems were hit with destructive malware that wiped computers. Ukrainian officials later said the website compromise appeared to begin with a supply-chain attack on an infrastructure software development company.
On 2022-02-04, Cisco Talos updated its analysis to incorporate CERT-UA and SSSCIP advisories. The update added findings that the attacks were intertwined with a broader disinformation effort and may have included false-flag elements intended to blame pro-Ukrainian actors or Poland.
On 2022-01-26, CERT-UA published an advisory on WhisperGate that described possible initial access vectors. It said a supply-chain compromise was the likely entry point, while not ruling out exploitation of OctoberCMS and Log4j vulnerabilities, and noted suspicious use of legitimate accounts and Impacket tools.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
justice.gov
Open sourcecyberscoop.com
Open sourceblog.gigamon.com
Open sourcenetskope.com
Open sourceblog.talosintelligence.com
Open sourceunit42.paloaltonetworks.com
Open sourcethehackernews.com
Open sourceedition.cnn.com
Open sourcecert.gov.ua
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.