Skip to main content
News Directory 3
  • Business
  • Entertainment
  • Health
  • News
  • Sports
  • Tech
  • World
Menu
  • Business
  • Entertainment
  • Health
  • News
  • Sports
  • Tech
  • World
PathWiper Malware: Ukraine Infrastructure Attack - News Directory 3

PathWiper Malware: Ukraine Infrastructure Attack

June 7, 2025 Catherine Williams Tech
News Context
At a glance
  • A newly discovered data wiper ⁢malware,dubbed "PathWiper," is being deployed in ‍targeted attacks against critical infrastructure in Ukraine.
  • According to Cisco Talos researchers, the PathWiper payload was delivered using a legitimate endpoint administration tool, suggesting the attackers previously gained administrative privileges.
  • The destructive⁣ capabilities of PathWiper ⁤involve a Windows batch file ⁤launching a malicious VBScript (uacinstall.vbs), which then drops and executes the primary payload (sha256sum.exe).This⁤ execution mimics legitimate admin...
Original source: bleepingcomputer.com

A new cyber threat, PathWiper malware, is⁤ actively targeting Ukraine’s critical infrastructure, posing critically important operational⁢ risks. This ⁣data wiper,linked to a Russia-linked APT group,aims for disruption,destroying key system files to render systems unusable. PathWiper uses a legitimate tool to gain administrative access, and then overwrites key files, causing serious damage, and differing from other attacks by its ‍focus ⁤on disruption, not financial gain. The attack underscores the ongoing cyber warfare, as data wipers like PathWiper become a common weapon against Ukrainian‍ critical infrastructure. Cisco Talos has released tools to help ‍prevent infections, providing critical defense. Delve deeper into the specifics and understand⁢ the evolving cyber landscape wiht ⁤News Directory 3. Discover what’s next …


PathWiper Malware Hits Ukraine, Disrupting Critical Infrastructure












Key Points

  • New ‘PathWiper’ malware targets critical infrastructure in Ukraine.
  • Attackers gained administrative ‍access via a legitimate tool.
  • Cisco Talos ‍links ⁤PathWiper to a Russia-linked APT group.
  • The malware overwrites critical NTFS files, rendering⁤ systems inoperable.
  • The ⁤attacks focus on disruption, not‍ financial gain.

PathWiper Malware Targets critical Infrastructure in Ukraine

Updated June 07,2025
⁤ ⁤

A newly discovered data wiper ⁢malware,dubbed “PathWiper,” is being deployed in ‍targeted attacks against critical infrastructure in Ukraine. The malware aims to disrupt operations within the country.

According to Cisco Talos researchers, the PathWiper payload was delivered using a legitimate endpoint administration tool, suggesting the attackers previously gained administrative privileges. ⁢Talos attributes the attack with high confidence to⁣ a Russia-linked advanced ⁤persistent⁢ threat (APT) group. This ⁢PathWiper malware shares similarities with HermeticWiper,which was previously deployed in Ukraine by the Sandworm threat group.

The destructive⁣ capabilities of PathWiper ⁤involve a Windows batch file ⁤launching a malicious VBScript (uacinstall.vbs), which then drops and executes the primary payload (sha256sum.exe).This⁤ execution mimics legitimate admin tool behavior to‍ evade ⁢detection. Unlike⁤ HermeticWiper, PathWiper identifies all connected drives (local, network, dismounted) and abuses Windows apis to dismount volumes before overwriting critical NTFS structures.

PathWiper targets‍ key system files in the ‍NTFS root directory, including‍ the Master Boot Record (MBR), Master File Table ($MFT), $LogFile, and $Boot file.By overwriting these⁤ and other critical NTFS⁢ files with random⁤ bytes, PathWiper renders affected systems completely⁤ inoperable. These attacks do not involve extortion, indicating the ⁤sole purpose⁤ is destruction and operational disruption.

Since the start of the war, data wipers have become a common tool in attacks against Ukraine, with ⁤Russian threat actors frequently using them⁤ to disrupt critical operations. Other wipers ⁢used include DoubleZero,CaddyWiper,HermeticWiper,Isaacwiper,whisperkill,WhisperGate,and AcidRain.

What’s‍ next

Cisco⁤ talos has released ⁤file hashes and snort rules ‍to⁣ help organizations detect and prevent PathWiper infections before data corruption occurs. The continued use of data wiper malware⁢ highlights the ongoing cyber threat⁢ to Ukraine’s critical infrastructure.

Share this:

  • Share on Facebook (Opens in new window) Facebook
  • Share on X (Opens in new window) X

More on this

  • Palantir reports second-quarter revenue of 1.935 billion dollars
  • China Demands Copper Supply Guarantees for Anglo American Teck Merger Approval
  • South Korea Warns Ukraine of Further Measures Over POW Dispute (archynewsy.com)

Related

Search:

News Directory 3

News Directory 3 catalogs US newspapers, news services, newsstands and digital news outlets across all 50 states. Browse local publishers by city, state, or topic, and follow current headlines linked back to their original sources.

Quick Links

  • Disclaimer
  • Terms and Conditions
  • About Us
  • Advertising Policy
  • Contact Us
  • Cookie Policy
  • Editorial Guidelines
  • Privacy Policy

Browse by State

  • Alabama
  • Alaska
  • Arizona
  • Arkansas
  • California
  • Colorado

© 2026 News Directory 3. All rights reserved.
For contact, advertising, copyright, issues email: office@newsdirectory3.com