Security News > 2023 > January > Ukraine: Sandworm hackers hit news agency with 5 data wipers

Ukraine: Sandworm hackers hit news agency with 5 data wipers
2023-01-27 18:10

The Ukrainian Computer Emergency Response Team found a cocktail of five different data-wiping malware strains deployed on the network of the country's national news agency on January 17th. "As of January 27, 2023, 5 samples of malicious programs were detected, the functionality of which is aimed at violating the integrity and availability of information," CERT-UA said.

Their attempt to wipe out all the data on the news agency's systems failed.

The wipers only managed to destroy files on "Several data storage systems," which didn't impact Ukrinform's operations.

Sandworm has also used the CaddyWiper data wiper in another failed attack from April targeting a large Ukrainian energy provider.

In that attack, the Russian hackers used a similar tactic, deploying CaddyWiper to erase traces left by Industroyer ICS malware, together with three other wipers designed for Linux and Solaris systems, and tracked as Orcshred, Soloshred, and Awfulshred.

Since Russia invaded Ukraine in February 2022, multiple strains of data-wiping malware have been deployed on the networks of Ukrainian targets besides CaddyWiper.


News URL

https://www.bleepingcomputer.com/news/security/ukraine-sandworm-hackers-hit-news-agency-with-5-data-wipers/