PathWiper Malware: Ukraine Infrastructure Attack
- A newly discovered data wiper malware,dubbed "PathWiper," is being deployed in targeted attacks against critical infrastructure in Ukraine.
- According to Cisco Talos researchers, the PathWiper payload was delivered using a legitimate endpoint administration tool, suggesting the attackers previously gained administrative privileges.
- The destructive capabilities of PathWiper involve a Windows batch file launching a malicious VBScript (uacinstall.vbs), which then drops and executes the primary payload (sha256sum.exe).This execution mimics legitimate admin...
A new cyber threat, PathWiper malware, is actively targeting Ukraine’s critical infrastructure, posing critically important operational risks. This data wiper,linked to a Russia-linked APT group,aims for disruption,destroying key system files to render systems unusable. PathWiper uses a legitimate tool to gain administrative access, and then overwrites key files, causing serious damage, and differing from other attacks by its focus on disruption, not financial gain. The attack underscores the ongoing cyber warfare, as data wipers like PathWiper become a common weapon against Ukrainian critical infrastructure. Cisco Talos has released tools to help prevent infections, providing critical defense. Delve deeper into the specifics and understand the evolving cyber landscape wiht News Directory 3. Discover what’s next …
PathWiper Malware Targets critical Infrastructure in Ukraine
Updated June 07,2025
A newly discovered data wiper malware,dubbed “PathWiper,” is being deployed in targeted attacks against critical infrastructure in Ukraine. The malware aims to disrupt operations within the country.
According to Cisco Talos researchers, the PathWiper payload was delivered using a legitimate endpoint administration tool, suggesting the attackers previously gained administrative privileges. Talos attributes the attack with high confidence to a Russia-linked advanced persistent threat (APT) group. This PathWiper malware shares similarities with HermeticWiper,which was previously deployed in Ukraine by the Sandworm threat group.
The destructive capabilities of PathWiper involve a Windows batch file launching a malicious VBScript (uacinstall.vbs), which then drops and executes the primary payload (sha256sum.exe).This execution mimics legitimate admin tool behavior to evade detection. Unlike HermeticWiper, PathWiper identifies all connected drives (local, network, dismounted) and abuses Windows apis to dismount volumes before overwriting critical NTFS structures.
PathWiper targets key system files in the NTFS root directory, including the Master Boot Record (MBR), Master File Table ($MFT), $LogFile, and $Boot file.By overwriting these and other critical NTFS files with random bytes, PathWiper renders affected systems completely inoperable. These attacks do not involve extortion, indicating the sole purpose is destruction and operational disruption.
Since the start of the war, data wipers have become a common tool in attacks against Ukraine, with Russian threat actors frequently using them to disrupt critical operations. Other wipers used include DoubleZero,CaddyWiper,HermeticWiper,Isaacwiper,whisperkill,WhisperGate,and AcidRain.
What’s next
Cisco talos has released file hashes and snort rules to help organizations detect and prevent PathWiper infections before data corruption occurs. The continued use of data wiper malware highlights the ongoing cyber threat to Ukraine’s critical infrastructure.
