HermeticWiper

Last reviewed:

HermeticWiper is a type of malware designed to delete data on infected systems, rendering them inoperable. It emerged in February 2022 and is notable for its use in cyberattacks targeting organizations in Ukraine. HermeticWiper is characterized by its destructive capabilities, specifically targeting the master boot record (MBR) of a system to prevent it from booting. This malware is part of a broader category of wiper malware, which aims to destroy data rather than steal it. As of October 2023, cybersecurity organizations continue to monitor and develop strategies to detect and mitigate the impact of HermeticWiper.

Overview

HermeticWiper is a destructive malware that targets Windows operating systems. It gained attention due to its deployment in cyberattacks against Ukrainian organizations in early 2022. The malware's primary function is to overwrite critical system files and the master boot record, rendering the infected systems unbootable. This type of attack can cause significant operational disruptions, particularly in environments where data recovery processes are not robust. HermeticWiper is part of a broader trend of wiper malware used in politically motivated cyberattacks.

History

HermeticWiper was first identified in February 2022 during a series of cyberattacks against Ukrainian organizations. The timing of its deployment coincided with escalating geopolitical tensions in the region. Cybersecurity firms such as ESET and Symantec reported on the malware's activities, noting its destructive impact on affected systems. The name "HermeticWiper" is derived from a digital certificate used by the malware, which was issued to a company named "Hermetica Digital Ltd." This certificate was likely used to lend legitimacy to the malware, allowing it to bypass certain security checks.

Technical characteristics

HermeticWiper is designed to target Windows operating systems. It operates by overwriting the master boot record and other critical system files, which prevents the system from booting. The malware uses a driver to perform these operations, which is signed with a legitimate digital certificate. This certificate helps the malware evade detection by some security solutions. HermeticWiper also attempts to disable system recovery features, making it more difficult for victims to restore their systems. The malware's destructive nature means that it does not attempt to exfiltrate data or communicate with a command and control server.

Infection vector

The exact infection vector for HermeticWiper is not definitively known. However, it is believed that the malware was distributed through spear-phishing emails or other targeted attack methods. Spear-phishing involves sending emails that appear to be from a trusted source, tricking the recipient into opening a malicious attachment or clicking a harmful link. Once executed, HermeticWiper begins its destructive process, targeting the master boot record and other critical files.

Notable campaigns

HermeticWiper was notably used in cyberattacks against Ukrainian organizations in February 2022. These attacks coincided with increased geopolitical tensions in the region, suggesting a possible link between the malware's deployment and the broader political context. Cybersecurity firms such as ESET and Symantec have documented these attacks, highlighting the malware's destructive impact on affected systems. The use of HermeticWiper in these campaigns underscores the growing trend of using wiper malware in politically motivated cyberattacks.

Detection and mitigation

Detecting HermeticWiper involves monitoring for unusual activity on the network, such as attempts to overwrite the master boot record or disable system recovery features. Security solutions can be configured to alert administrators to these activities. Mitigation strategies include maintaining regular backups of critical data, implementing robust email filtering to prevent spear-phishing attacks, and ensuring that all systems are up-to-date with the latest security patches. Organizations are also advised to conduct regular security training for employees to help them recognize and avoid phishing attempts.

Timeline of HermeticWiper Development and Attacks

HermeticWiper Attack Process

See also

Sources

Categories: Malware
Last updated: September 4, 2026