Ukraine said Russia-linked threat groups intensified cyberattacks against its critical infrastructure, government, communications, energy, and humanitarian logistics networks, using phishing and multiple destructive malware families including HermeticWiper, IsaacWiper, CaddyWiper, and DoubleZero. CERT-UA attributed activity during the period to several tracked clusters such as UAC-0056, UAC-0051/UNC1151, UAC-0028/APT28, and UAC-0033/XDSpy, and said the operations were tied to actors affiliated with Russian and Belarusian state structures and proxy entities. Ukrainian officials also reported targeting of organizations documenting war crimes and of European charities supporting refugees, underscoring that the campaign extended beyond domestic wartime targets.
Researchers separately documented destructive intrusions in which HermeticWiper and CaddyWiper were deployed through Windows Group Policy after attackers had already gained broad control of victim networks. HermeticWiper hit finance organizations, government contractors, and other Ukrainian systems while also affecting some machines in Latvia and Lithuania; it corrupted local data and the master boot record, leaving devices unable to boot. In parallel, CERT-UA warned that phishing emails posing as antivirus updates delivered Cobalt Strike along with the GraphSteel and GrimPlant backdoors, a campaign linked with medium confidence to UAC-0056, showing that espionage, access operations, and destructive attacks were being conducted in tandem.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
Ukrainian officials said some of the same hackers targeting Ukraine were also attacking European charity and other EU organizations assisting Ukrainian refugees. They described this as evidence that the cyberwar was spreading beyond Ukraine into broader European and NATO cyberspace.
CERT-UA attributed the March 15–22 attacks on Ukraine’s critical information infrastructure to numerous tracked clusters including UAC-0056, UAC-0051/UNC1151, UAC-0010, UAC-0082, UAC-0088, UAC-0035, UAC-0041, UAC-0020/Vermin, UAC-0028/APT28, UAC-0026, UAC-0086, UAC-0084/TA416, UAC-0064, and UAC-0033/XDSpy. The activity was said to involve organizations affiliated with Russian, Belarusian, and so-called LNR security services.
Between March 15 and March 22, 2022, Ukraine observed cyberattacks targeting government, energy, communications, and humanitarian logistics systems, along with organizations publishing war-crimes information. Officials said at least four wiper families—HermeticWiper, IsaacWiper, CaddyWiper, and DoubleZero—were used, alongside phishing campaigns.
Russia's National Computer Incident Response and Coordination Center warned operators of critical information infrastructure about an increase in computer attacks as the invasion of Ukraine entered its second day. The warning came amid outages affecting Russian government and banking websites, including mil.ru, kremlin.ru, and duma.gov.ru.
ESET discovered the HermeticWizard worm being used to drop HermeticWiper payloads on the day Russia invaded Ukraine. The malware formed part of the destructive campaign against Ukrainian networks.
ESET said the HermeticWiper attack was first seen around 16:52 Ukraine time on February 23, 2022, affecting targets including finance organizations and government contractors. Some spillover infections were also reported in Latvia and Lithuania.
Microsoft found the WhisperGate wiper being used in data-wiping attacks against Ukrainian organizations in mid-January 2022. The malware was disguised as ransomware and coincided with coordinated defacements of Ukrainian government websites.
CERT-UA-linked reporting said UAC-0056 had stepped up phishing distribution and network-compromise activity targeting Ukrainian organizations since December 2021. The actor was described as a Russian-speaking APT aligned with Russian state interests.
ESET observed the newly discovered CaddyWiper data wiper on a few dozen systems in a limited number of Ukrainian organizations. The malware was deployed via Group Policy Objects and spared domain controllers, suggesting attackers already controlled victim networks.
CERT-UA warned that phishing emails impersonating Ukrainian government agencies were distributing a fake Bitdefender update to install Cobalt Strike plus the GraphSteel and GrimPlant backdoors. The activity was associated with UAC-0056 with medium confidence.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
trellix.com
Open sourcecip.gov.ua
Open sourcenextgov.com
Open sourcebleepingcomputer.com
Open sourcebleepingcomputer.com
Open sourcethehackernews.com
Open sourcetherecord.media
Open sourcewelivesecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.