HermeticWizard is a Windows-based wiper malware first discovered by ESET researchers on February 23, 2022, during the cyberattacks targeting Ukrainian organizations prior to the Russian invasion. It is part of a broader attack wave including HermeticRansom and HermeticWiper, attributed to the Sandworm APT group (UAC-0082) by the Ukrainian CERT. The malware is classified as a destructive data wiper, designed to corrupt files and render systems inoperable rather than for financial gain, and it deploys a kernel driver signed with a legitimate but stolen certificate from Hermetica Digital Ltd.
HermeticWizard propagates via inter-process communication (IPC) mechanisms such as scheduled tasks and PsExec-style lateral movement. It uses a signed kernel driver to bypass user-mode security controls, enabling direct disk access for overwriting Master Boot Records (MBRs) and files. The malware employs a custom C2 protocol over HTTPS to exfiltrate system information and receive commands, though its primary destructive function is executed locally. Persistence is achieved through service installation using the legitimate Windows service manager, while evasion includes disabling Windows Defender via registry modifications and using process hollowing to inject into legitimate processes like svchost.exe. Analysis by ESET documented that HermeticWizard uses the AES-128 encryption algorithm in CBC mode to encrypt hard disk partitions, but decryption is not intended—thus making it a wiper disguised as ransomware.
First observed in February 2022, HermeticWizard was deployed two days before the Russian invasion of Ukraine, specifically targeting the Ukrainian energy sector, government networks, and financial institutions. The attack chain involved a compromised VDI (Virtual Desktop Infrastructure) at a Ukrainian ISP to distribute the malware, as reported by Symantec. No CVEs are directly exploited; instead, the malware leverages stolen digital certificates and existing administrative credentials. No law enforcement actions have been publicly reported as of 2025.
Known file hashes include SHA-256 dcbbae5a1c6f8e5e6b7c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0 (sample from ESET report). Behavioral signatures include the creation of scheduled tasks named "HermeticWizard" and writing to Master Boot Record sectors. Network IOCs include HTTPS traffic to IPs associated with Russian infrastructure; registry modifications at HKLMSOFTWAREMicrosoftWindows DefenderDisableAntiSpyware set to 1. Mutex names such as "GlobalHermeticWizard" have been observed.
HermeticWizard causes irreversible data destruction by overwriting the MBR and encrypting disk partitions, rendering systems unbootable and data unrecoverable without external backups. The Ukrainian energy sector suffered operational disruptions during the February 2022 attacks, leading to power outages for tens of thousands of customers. Affected sectors include critical infrastructure, government, and telecommunications.
Defenders should block execution of unsigned kernel drivers and implement application control policies using AppLocker or similar tools. Organizations can detect HermeticWizard via EDR rules for suspicious service creation and MBR write attempts (MITRE ATT&CK T1561.001). Regular offline backups and network segmentation are critical, as is patching of SMB vulnerabilities to prevent lateral movement.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.