WhisperGate targeted Ukrainian government, non-profit, and IT organizations with destructive malware disguised as ransomware. Microsoft first observed the operation on January 13, 2022, and identified dozens of affected systems, warning that the visible impact likely understated its scope. The two-stage toolchain overwrote the Master Boot Record with a fraudulent ransom note, then downloaded a file-corrupting payload through Discord infrastructure. The malware offered no recovery mechanism: its purpose was to render devices inoperable, not collect ransom payments. Microsoft initially tracked the operation as DEV-0586, later renamed Cadet Blizzard, and added WhisperGate detections to Defender products.
Subsequent reporting associated WhisperGate with the suspected Russian state-sponsored Ember Bear/Nodaria threat ecosystem and catalogued an arsenal including Graphiron, GrimPlant, GraphSteel, OutSteel, SaintBot, BabaDeda, and Cobalt Strike Beacon. These reports described espionage campaigns primarily targeting Ukraine and Georgia, using spear-phishing and multistage malware to steal documents, credentials, screenshots, and SSH-related data; Symantec separately reported Graphiron information-stealing activity against Ukraine. Recommended defenses against WhisperGate include investigating published indicators and unusual remote authentication, blocking known malicious hashes, assessing restrictions on Discord infrastructure, enabling MFA, maintaining endpoint protection, patching exposed services, and keeping offline backups to support recovery from destructive attacks.

TTPs, infrastructure, and targeting history in one profile.
16 events from the most recent confirmed update back to the earliest known activity.
Contagio published a catalog covering Graphiron, GrimPlant, GraphSteel, OutSteel, BabaDeda, SaintBot, Cobalt Strike Beacon and WhisperGate. The article listed a collection of 218 samples totaling 209 MB, with MD5, SHA-1 and SHA-256 hash tables.
CERT-UA again reported phishing attacks targeting Ukrainian government organizations with GraphSteel and GrimPlant.
CERT-UA reported further phishing attacks against Ukrainian government organizations using GraphSteel and GrimPlant.
Mandiant identified a likely UNC2589 phishing campaign that used a malicious spreadsheet macro to deliver GrimPlant and GraphSteel.
CERT-UA reported phishing attacks against Ukrainian government organizations involving the GraphSteel information stealer and GrimPlant backdoor.
Mandiant identified a likely UNC2589 phishing campaign using evacuation themes. The campaign installed Remote Utilities and established persistence through a startup service.
A malicious Word attachment induced JavaScript and PowerShell execution to download a loader. The infection chain deployed OutSteel, SaintBot, a Windows Defender-disabling batch script and a legitimate Google Chrome installer.
ReliaQuest recorded identification and an advisory update on January 16, classifying WhisperGate as a high-severity destructive malware threat. The advisory documented its boot-record wiping and file-corruption stages and provided defensive guidance.
Microsoft first observed the destructive operation on January 13; other reporting described destructive attacks on January 14 and campaign activity on January 15. The malware affected Ukrainian government, nonprofit and technology organizations, overwriting boot records and corrupting files while masquerading as ransomware.
A campaign used political-themed Word documents against Georgian government officials. Document macros created a C# dropper that delivered an AutoIt document-stealing Trojan.
Researchers identified phishing against Ukrainian government entities that they subsequently linked to a similar July 2021 campaign targeting Georgian officials.
Ember Bear, also tracked as Nodaria, UNC2589 and UAC-0056, was described as active since at least March 2021. The suspected Russian state-sponsored group primarily targeted Ukraine and Georgia.
An April 2023 update identified Cadet Blizzard as the new name for DEV-0586 under Microsoft's weather-themed threat actor taxonomy.
Mandiant attributed the January 14, 2022 destructive Ukrainian attack using PAYWIPE, also called WhisperGate, to UNC2589. The source does not specify when Mandiant made this attribution.
ReliaQuest added indicators associated with WhisperGate to its Emergency Feed to support detection and blocking.
Microsoft reported dozens of impacted systems and initially tracked the activity as DEV-0586. Its report detailed the fake ransom note, Discord-hosted file-corrupting payload and indicators of compromise, and stated that Microsoft Defender protections had been implemented.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 285 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
contagiodump.blogspot.com
Open sourcereliaquest.com
Open sourcemicrosoft.com
Open sourcesymantec-enterprise-blogs.security.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.