Spectra Assure Free Trial
Get your 14-day free trial of Spectra Assure for Software Supply Chain Security
Get Free TrialMore about Spectra Assure Free TrialThis third wiper malware was also discovered by ESET researchers, but two weeks after Russia advanced its military into Ukraine. The firm found that the malware was compiled just two hours before its deployment.
CaddyWiper destroys user data and partitions from attached drives, similar to its predecessors. However, this malware family does not share major coding similarities with either HermeticWiper or IsaacWiper, and it stands alone in lacking a digital signature. The malware’s other unique trait is that it does not destroy domain controllers. This is probably a way for attackers to hold onto their access to an organization’s systems while continuing to disturb the entity’s operations, according to ESET. So far the wiper malware has been used to target systems belonging to a variety of entities, both in the government and financial sectors of Ukraine.
Link: Win32.Trojan.CaddyWiper.yara
ReversingLabs’ team of analysts are constantly surveying the threat landscape in an effort to better serve our customers and the greater security community. As the situation in Ukraine continues to evolve, we will continue to update you about new threats, attacks and threat indicators. Don’t hesitate to contact us if you’d like to learn more about how we help organizations combat threats like malicious wipers and ransomware or to schedule a demonstration.

SVGs are difficult to detect, can be snuck into content — and can do malicious and legitimate actions. Here's how malicious SVGs work.
One of the most effective attack methods I've analyzed this year runs on legitimate tools and willing users — and AV and EDR is blind to it.


