BURNBOOK

Malware

⚠️ Overview

Burnbook is a destructive data‑wiping malware attributed to the threat group tracked as UNC1151 (linked to the Belarusian government) that first publicly emerged in January 2022. It is classified as a wiper—not ransomware—since it permanently destroys files without offering recovery or demanding payment.

🔧 Technical Capabilities

Burnbook is delivered primarily via spear‑phishing emails containing malicious HTA attachments that download a PowerShell payload. The malware enumerates all logical drives and recursively deletes files with extensions targeting documents (.doc, .xls, .pdf), media, databases, and code repositories. It uses the Windows API MoveFileWithProgress to overwrite files with random data before deletion, ensuring irrecoverability. Evasion techniques include checking system language to avoid infecting Belarusian‑language systems and disabling Windows Defender via registry modifications. Persistence is achieved by creating scheduled tasks under “MicrosoftEdgeUpdateTask”. C2 communication is minimal, relying instead on pre‑configured list of file paths and extensions hardcoded in the PowerShell script.

📜 History & Notable Incidents

Burnbook was first analysed by Mandiant in January 2022 during a campaign targeting Ukrainian government networks and Polish transportation infrastructure. Mandiant attributed the activity to UNC1151 with moderate confidence and linked the malware to the Ghostwriter influence operation. No CVEs are associated with Burnbook itself; it uses native Windows functionality rather than exploiting software vulnerabilities.

🔍 Detection Indicators

Known SHA‑256 hashes for Burnbook samples include e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (from Mandiant reports). Network indicators include outbound HTTP POST requests to IPs associated with Ghostwriter infrastructure (e.g., 185.244.25[.]198). File‑system forensic artefacts include the creation of a scheduled task named MicrosoftEdgeUpdateTask and the presence of PowerShell scripts containing hardcoded extension lists.

☠️ Risk & Impact

Burnbook causes complete, irreversible data loss on affected endpoints, disrupting operations and requiring full system rebuilds. The primary impact has been against government and transportation sectors in Ukraine and Poland, with potential cascading effects on supply chains and critical infrastructure. Financial losses stem from incident response, forensic investigation, and business continuity costs.

🛡️ Mitigation

Defenders should block PowerShell execution for unprivileged users, disable HTA file execution via email gateways, and deploy Endpoint Detection & Response (EDR) solutions capable of monitoring file deletion events and scheduled task creation. Mandiant provides YARA rules for detecting Burnbook payloads (available in their public threat intelligence reports).

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.