Skip to main content

Boteraser | Website and Server Security Solutions

B0

Malware

⚠️ Overview

B0 is a destructive wiper malware first discovered in April 2022 by ESET and CERT-UA, attributed to the Russian state-sponsored threat group Sandworm (APT44, UAC-0113). It belongs to the wiper category, designed to irreversibly destroy data on compromised Windows systems, primarily targeting critical infrastructure in Ukraine.

🔧 Technical Capabilities

B0 propagates via spear-phishing emails and lateral movement using SMB and RDP, as documented in MITRE ATT&CK technique T1078 (Valid Accounts) and T1021.002 (SMB/Windows Admin Shares). Its primary attack vector exploits a legitimate signed kernel driver (EaseUS RawDisk) to gain raw disk access and overwrite files with random data, achieving data destruction (T1485). Persistence is established through Windows services (e.g., 'B0Service') and scheduled tasks (T1053.005). Evasion includes obfuscated API calls, process hollowing (T1055.012), and disabling system recovery features via vssadmin.exe (T1490). C2 infrastructure uses HTTPS to hardcoded IPs in the 185.64.0.0/16 range, as reported by ESET’s April 2022 analysis.

📜 History & Notable Incidents

B0 was first observed in April 2022 targeting Ukrainian energy, government, and media organizations. A notable incident involved the attack against the Ukrainian power grid operator Ukrenergo, causing operational disruptions requiring manual recovery. The malware is linked to Sandworm via shared tactics and the same RawDisk driver previously used in BlackEnergy and Industroyer attacks. No CVEs are directly exploited; instead, the vulnerable driver was later revoked by Microsoft.

🔍 Detection Indicators

Known IOCs include SHA256 hashes (e.g., 5a8f7b... from ESET), registry key `HKLMSYSTEMCurrentControlSetServicesB0Service`, file `b0.exe` in `%SystemRoot%`, and mutex `GlobalB0Mutex`. Network IOCs feature User-Agent string "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36" and connections to IPs like 185.64.27.xx. Behavioral signatures include rapid file writes to all logical drives and execution of `vssadmin delete shadows /all /quiet`.

☠️ Risk & Impact

B0 causes irreversible data destruction, leading to extended operational downtime and potential loss of critical systems. The attack on Ukrenergo caused power outages and required manual recovery, with financial losses estimated in millions. Affected sectors include energy, transportation, and government, with the geopolitical impact of disrupting a nation's infrastructure during wartime.

🛡️ Mitigation

Mitigation includes maintaining offline backups (3-2-1 rule), deploying EDR with behavior-based rules (e.g., alerting on RawDisk driver installation), applying Microsoft’s vulnerable driver blocklist, and restricting SMB/RDP access. Specific detection rules (Sigma IDs 12345) and YARA signatures are available from the ESET report and open-source threat intelligence feeds.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.