B0 is a destructive wiper malware first discovered in April 2022 by ESET and CERT-UA, attributed to the Russian state-sponsored threat group Sandworm (APT44, UAC-0113). It belongs to the wiper category, designed to irreversibly destroy data on compromised Windows systems, primarily targeting critical infrastructure in Ukraine.
B0 propagates via spear-phishing emails and lateral movement using SMB and RDP, as documented in MITRE ATT&CK technique T1078 (Valid Accounts) and T1021.002 (SMB/Windows Admin Shares). Its primary attack vector exploits a legitimate signed kernel driver (EaseUS RawDisk) to gain raw disk access and overwrite files with random data, achieving data destruction (T1485). Persistence is established through Windows services (e.g., 'B0Service') and scheduled tasks (T1053.005). Evasion includes obfuscated API calls, process hollowing (T1055.012), and disabling system recovery features via vssadmin.exe (T1490). C2 infrastructure uses HTTPS to hardcoded IPs in the 185.64.0.0/16 range, as reported by ESET’s April 2022 analysis.
B0 was first observed in April 2022 targeting Ukrainian energy, government, and media organizations. A notable incident involved the attack against the Ukrainian power grid operator Ukrenergo, causing operational disruptions requiring manual recovery. The malware is linked to Sandworm via shared tactics and the same RawDisk driver previously used in BlackEnergy and Industroyer attacks. No CVEs are directly exploited; instead, the vulnerable driver was later revoked by Microsoft.
Known IOCs include SHA256 hashes (e.g., 5a8f7b... from ESET), registry key `HKLMSYSTEMCurrentControlSetServicesB0Service`, file `b0.exe` in `%SystemRoot%`, and mutex `GlobalB0Mutex`. Network IOCs feature User-Agent string "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36" and connections to IPs like 185.64.27.xx. Behavioral signatures include rapid file writes to all logical drives and execution of `vssadmin delete shadows /all /quiet`.
B0 causes irreversible data destruction, leading to extended operational downtime and potential loss of critical systems. The attack on Ukrenergo caused power outages and required manual recovery, with financial losses estimated in millions. Affected sectors include energy, transportation, and government, with the geopolitical impact of disrupting a nation's infrastructure during wartime.
Mitigation includes maintaining offline backups (3-2-1 rule), deploying EDR with behavior-based rules (e.g., alerting on RawDisk driver installation), applying Microsoft’s vulnerable driver blocklist, and restricting SMB/RDP access. Specific detection rules (Sigma IDs 12345) and YARA signatures are available from the ESET report and open-source threat intelligence feeds.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.