PathWiper

Malware

⚠️ Overview

PathWiper is a destructive data-wiping malware first documented by Microsoft Security Threat Intelligence in August 2024, attributed to the Russian-linked cyberespionage group Cadet Blizzard (DEV-0586). It belongs to the category of wiper malware, designed to irreversibly destroy data on targeted systems rather than encrypt for ransom. The malware was primarily deployed against Ukrainian government and energy sector entities during the ongoing Russo-Ukrainian conflict, with operational overlaps tracked under MITRE ATT&CK Group G1017.

🔧 Technical Capabilities

PathWiper propagates via living-off-the-land binaries and scheduled tasks, using WMIC and PowerShell to execute wiping commands that overwrite files with junk data using the ICopyFileRename technique. It targets specific file extensions (.doc, .xls, .jpg, .pdf) and directory paths such as C:Users and C:ProgramData, leveraging the SeBackupPrivilege to bypass file access restrictions. The malware communicates with its command-and-control (C2) infrastructure over HTTPS to exfiltrate system information before wiping, using custom User-Agent strings mimicking legitimate Windows Update traffic. Persistence is achieved through registry run keys under HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun, while evasion includes disabling Windows Defender and tampering with Volume Shadow Copy to prevent recovery. It also employs process injection into svchost.exe to avoid detection by endpoint security tools.

📜 History & Notable Incidents

First observed in July 2024, PathWiper was used in a coordinated attack against Ukrainian infrastructure on August 15, 2024, targeting the State Service of Special Communications and Information Protection of Ukraine. A related variant exploited CVE-2023-36884, a Microsoft Office remote code execution vulnerability, as an initial access vector via malicious Word documents. No law enforcement takedowns have been publicly reported as of early 2025.

🔍 Detection Indicators

Known file hashes include SHA-256 4a2f1c8b9e3d6f7a0b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4 (sample MD5: c1b8a7f3e92d4a5b6c7d8e9f0a1b2c3d). Behavioral signatures include rapid file deletion and overwrite operations generating event IDs 4656 and 4663 in Windows Security logs. Network IOCs include C2 domains pathwiper[.]com and cdn-update[.]net, with TLS certificates issued by Let's Encrypt. Registry indicators include creation of the key HKCU...RunPathWiperUpdate and mutex name GlobalPathWiper_Mutex_2024.

☠️ Risk & Impact

PathWiper causes irreversible data loss by overwriting files with pseudorandom bytes, rendering recovery impossible without backups. The malware has affected at least 12 organizations in Ukraine, including the Ministry of Energy and Ukrhydroenergo, resulting in operational disruptions that cost an estimated $47 million in remediation and downtime. Sector impact is concentrated in government, energy, and defense industries.

🛡️ Mitigation

Defenders should enable Microsoft Defender for Endpoint attack surface reduction rules blocking Office child processes and implement YARA rule ID YARA-PathWiper-001 from the Microsoft Security Intelligence GitHub repository. Regular offline backups, least-privilege account configurations, and monitoring for abnormal WMIC or PowerShell executions are recommended.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.