LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0689: WhisperGate

WhisperGate is a multi-stage wiper designed to look like ransomware that has been used against multiple government, non-profit, and information technology organizations in Ukraine since at least January 2022.[1][2][3]

EnterpriseS0689MalwareObject v1.2Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

WhisperGate matters because ATT&CK describes it as a multi-stage Windows wiper designed to look like ransomware and used against government, non-profit, and IT organizations in Ukraine since at least January 2022. For leaders, the key decision point is not ransom negotiation readiness; it is destructive-malware resilience: can the organization identify suspicious execution early, preserve evidence, isolate affected systems, and restore critical services from trusted backups if data or disk content is destroyed?

Executive priority

Treat this as a resilience and incident-command scenario. The ATT&CK relationships connect WhisperGate to execution via PowerShell, Windows Command Shell, Visual Basic, Native API, and InstallUtil; stealth through masquerading, encoded files, process hollowing, token-based process creation, and cleanup; discovery of files, shares, systems, and security tools; command-and-control over web services/protocols; and impact through data destruction, disk content wiping, and shutdown/reboot. Executives should ask whether destructive-malware playbooks, backup recovery evidence, endpoint visibility, privileged access controls, and crisis communications are tested for a fast-moving Windows incident.

Technical view

SOC and IR teams should validate coverage around the mapped behaviors rather than relying on a single malware signature, especially because the official ATT&CK object provides no dedicated detection text. Focus on Windows execution telemetry for PowerShell, cmd, VB-related execution, Native API-heavy behavior, InstallUtil proxy execution, suspicious process hollowing, and processes created with alternate tokens. Correlate those signals with file/share discovery, security software discovery, ingress tool transfer, web-based C2 patterns, file deletion, reboot activity, and destructive writes consistent with data or disk-content wiping. ATT&CK also relates WhisperGate to Ember Bear use; use that as threat-intelligence context, not as automatic attribution for local incidents.

Likely telemetry

  • Windows endpoint process creation and command-line telemetry
  • PowerShell script block/module/transcription logs where enabled
  • Windows Command Shell execution records
  • VB/script execution evidence
  • InstallUtil execution and .NET binary load activity

Detection direction

  • Build behavior-based detections around the ATT&CK relationships: suspicious script execution, proxy execution through InstallUtil, encoded/deobfuscated content, masqueraded binaries, process hollowing, token-based process creation, and unusual file/share discovery.
  • Tune impact detections for destructive patterns: rapid file deletion or overwrite, disk-content wipe indicators, unexpected shutdown/reboot activity, and combinations of discovery followed by destructive writes.
  • Correlate endpoint and network signals. Web protocols and legitimate web services can be noisy, so detections should consider unusual process lineage, newly transferred tools, rare destinations, and timing relative to local execution.
  • Validate blind spots explicitly: missing PowerShell logging, incomplete command-line capture, limited memory/process telemetry, weak SMB/share enumeration visibility, lack of disk-write monitoring, and backup systems not monitored for tampering or destructive activity.
  • Use the Ember Bear relationship as enrichment for threat hunting and reporting context, while avoiding automatic attribution without local evidence.

Mitigation priorities

  • Prioritize tested, offline or otherwise resilient backups for critical Windows systems and business data; confirm restore speed and integrity, not just backup existence.
  • Harden and monitor administrative execution paths: PowerShell, cmd, VB/script execution, InstallUtil, and other trusted utilities that can proxy execution.
  • Apply least privilege and privileged access controls to reduce the value of token abuse and unauthorized destructive actions.
  • Segment critical services and restrict unnecessary access to network shares to limit discovery and propagation opportunities.
  • Ensure endpoint detection, logging, and incident response processes can preserve evidence and isolate hosts quickly during suspected destructive activity.
Additional notes and limits

The official ATT&CK description identifies WhisperGate as a multi-stage wiper made to resemble ransomware and used against multiple Ukrainian government, non-profit, and IT organizations. ATT&CK relationships provide the most useful defensive context: execution, stealth, discovery, command-and-control, and impact behaviors. Because no official detection guidance is supplied, this take emphasizes validation of telemetry and behavior coverage rather than claiming specific detection efficacy.

This assessment is limited to the supplied ATT&CK STIX fields, external references, and relationships. The object lists Windows as the malware platform and does not provide official detection text, aliases, or tactics for the malware object itself. Local conclusions require environment-specific evidence such as logs, endpoint alerts, file samples, network records, and recovery-test results.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

WhisperGate

WhisperGate is a multi-stage wiper designed to look like ransomware that has been used against multiple government, non-profit, and information technology organizations in Ukraine since at least January 2022.[1][2][3]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

28 rows
DomainIDNameRelationship / procedure
EnterpriseT1542.003BootkitSub-technique

WhisperGate overwrites the MBR with a bootloader component that performs destructive wiping operations on hard drives and displays a fake ransom note when the host boots.[4][1][3][5][6]

EnterpriseT1620Reflective Code Loading

WhisperGate's downloader can reverse its third stage file bytes and reflectively load the file as a .NET assembly.[7]

EnterpriseT1485Data Destruction

WhisperGate can corrupt files by overwriting the first 1 MB with `0xcc` and appending random extensions.[3][4][1][2][5][6]

EnterpriseT1685Disable or Modify Tools

WhisperGate can download and execute AdvancedRun.exe to disable the Windows Defender Theat Protection service and set an exclusion path for the C:\ drive.[2][5][6]

EnterpriseT1083File and Directory Discovery

WhisperGate can locate files based on hardcoded file extensions.[3][2][5][6]

EnterpriseT1059.001PowerShellSub-technique

WhisperGate can use PowerShell to support multiple actions including execution and defense evasion.[2][5][6]

EnterpriseT1218.004InstallUtilSub-technique

WhisperGate has used `InstallUtil.exe` as part of its process to disable Windows Defender.[2]

EnterpriseT1027.013Encrypted/Encoded FileSub-technique

WhisperGate can Base64 encode strings, store downloaded files in reverse byte order, and use the Eazfuscator tool to obfuscate its third stage.[5][6][7]

EnterpriseT1106Native API

WhisperGate has used the `ExitWindowsEx` to flush file buffers to disk and stop running processes and other API calls.[5][7]

EnterpriseT1071.001Web ProtocolsSub-technique

WhisperGate can make an HTTPS connection to download additional files.[2][6]

EnterpriseT1070.004File DeletionSub-technique

WhisperGate can delete tools from a compromised host after execution.[5]

EnterpriseT1561.002Disk Structure WipeSub-technique

WhisperGate can overwrite the Master Book Record (MBR) on victim systems with a malicious 16-bit bootloader.[3][4][1][2][5][6]

EnterpriseT1561.001Disk Content WipeSub-technique

WhisperGate can overwrite sectors of a victim host's hard drive at periodic offsets.[4][5][6]

EnterpriseT1497.001System ChecksSub-technique

WhisperGate can stop its execution when it recognizes the presence of certain monitoring tools.[2]

EnterpriseT1518.001Security Software DiscoverySub-technique

WhisperGate can recognize the presence of monitoring tools on a target system.[2]

EnterpriseT1135Network Share Discovery

WhisperGate can enumerate connected remote logical drives.[5]

EnterpriseT1569.002Service ExecutionSub-technique

WhisperGate can download and execute AdvancedRun.exe via `sc.exe`.[6][2]

EnterpriseT1529System Shutdown/Reboot

WhisperGate can shutdown a compromised host through execution of `ExitWindowsEx` with the `EXW_SHUTDOWN` flag.[5]

EnterpriseT1055.012Process HollowingSub-technique

WhisperGate has the ability to inject its fourth stage into a suspended process created by the legitimate Windows utility `InstallUtil.exe`.[5][7]

EnterpriseT1059.003Windows Command ShellSub-technique

WhisperGate can use `cmd.exe` to execute commands.[2]

EnterpriseT1059.005Visual BasicSub-technique

WhisperGate can use a Visual Basic script to exclude the `C:\` drive from Windows Defender.[2][5]

EnterpriseT1134.002Create Process with TokenSub-technique

The WhisperGate third stage can use the AdvancedRun.exe tool to execute commands in the context of the Windows TrustedInstaller group via `%TEMP%\AdvancedRun.exe" /EXEFilename "C:\Windows\System32\sc.exe" /WindowState 0 /CommandLine "stop WinDefend" /StartDirectory "" /RunAs 8 /Run`.[5]

EnterpriseT1102Web Service

WhisperGate can download additional payloads hosted on a Discord channel.[4][2][3][5][6]

EnterpriseT1680Local Storage Discovery

WhisperGate has the ability to enumerate fixed logical drives on a targeted system.[5]

EnterpriseT1497.003Time Based ChecksSub-technique

WhisperGate can pause for 20 seconds to bypass antivirus solutions.[6][7]

EnterpriseT1140Deobfuscate/Decode Files or Information

WhisperGate can deobfuscate downloaded files stored in reverse byte order and decrypt embedded resources using multiple XOR operations.[5][6]

EnterpriseT1036Masquerading

WhisperGate has been disguised as a JPG extension to avoid detection as a malicious PE file.[6]

EnterpriseT1105Ingress Tool Transfer

WhisperGate can download additional stages of malware from a Discord CDN channel.[3][2][5][6]

Associated objects

Groups, software, and campaigns

GroupEnterprise

G1003: Ember Bear

Ember Bear is a Russian state-sponsored cyber espionage group that has been active since at least 2020, linked to Russia's General Staff Main Intelligence Directorate (GRU) 161st Specialist Training Center (Unit 29155).[1] Ember Bear has primarily focused operations against Ukrainian government and telecommunication entities, but has also operated against critical infrastructure entities in Europe and the Americas.[2] Ember Bear conducted the WhisperGate destructive wiper attacks against Ukraine in early 2022.[3][4][1] There is some confusion as to whether Ember Bear overlaps with another Russian-linked entity referred to as Saint Bear. At present available evidence strongly suggests these are distinct activities with different behavioral profiles.[2][5]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.2
Created
Modified
Raw hash
c9b8d35915782b10...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.2Current bundlec9b8d3591578…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Cybereason WhisperGate February 2022

    Cybereason Nocturnus. (2022, February 15). Cybereason vs. WhisperGate and HermeticWiper. Retrieved March 10, 2022.

    Open source URL
  2. [2]
    Unit 42 WhisperGate January 2022

    Falcone, R. et al.. (2022, January 20). Threat Brief: Ongoing Russia and Ukraine Cyber Conflict. Retrieved March 10, 2022.

    Open source URL
  3. [3]
    Microsoft WhisperGate January 2022

    MSTIC. (2022, January 15). Destructive malware targeting Ukrainian organizations. Retrieved March 10, 2022.

    Open source URL
  4. [4]
    Crowdstrike WhisperGate January 2022

    Crowdstrike. (2022, January 19). Technical Analysis of the WhisperGate Malicious Bootloader. Retrieved March 10, 2022.

    Open source URL
  5. [5]
    Cisco Ukraine Wipers January 2022

    Biasini, N. et al.. (2022, January 21). Ukraine Campaign Delivers Defacement and Wipers, in Continued Escalation. Retrieved March 14, 2022.

    Open source URL
  6. [6]
    Medium S2W WhisperGate January 2022

    S2W. (2022, January 18). Analysis of Destructive Malware (WhisperGate) targeting Ukraine. Retrieved March 14, 2022.

    Open source URL
  7. [7]
    RecordedFuture WhisperGate Jan 2022

    Insikt Group. (2020, January 28). WhisperGate Malware Corrupts Computers in Ukraine. Retrieved September 16, 2024.

    Open source URL
  8. [8]
    Cadet Blizzard emerges as novel threat actor

    Microsoft Threat Intelligence. (2023, June 14). Cadet Blizzard emerges as a novel and distinct Russian threat actor. Retrieved July 10, 2023.

    Open source URL
  9. [9]
    CrowdStrike Ember Bear Profile March 2022

    CrowdStrike. (2022, March 30). Who is EMBER BEAR?. Retrieved June 9, 2022.

    Open source URL
  10. [10]
    Mandiant UNC2589 March 2022

    Sadowski, J; Hall, R. (2022, March 4). Responses to Russia's Invasion of Ukraine Likely to Spur Retaliation. Retrieved June 9, 2022.

    Open source URL
  11. [11]
    Cybereason WhisperGate February 2022

    Cybereason Nocturnus. (2022, February 15). Cybereason vs. WhisperGate and HermeticWiper. Retrieved March 10, 2022.

    Open source URL
  12. [12]
    Cybereason WhisperGate February 2022

    Cybereason Nocturnus. (2022, February 15). Cybereason vs. WhisperGate and HermeticWiper. Retrieved March 10, 2022.

    Open source URL
  13. [13]
    Microsoft WhisperGate January 2022

    MSTIC. (2022, January 15). Destructive malware targeting Ukrainian organizations. Retrieved March 10, 2022.

    Open source URL
  14. [14]
    Microsoft WhisperGate January 2022

    MSTIC. (2022, January 15). Destructive malware targeting Ukrainian organizations. Retrieved March 10, 2022.

    Open source URL
  15. [15]
    Unit 42 WhisperGate January 2022

    Falcone, R. et al.. (2022, January 20). Threat Brief: Ongoing Russia and Ukraine Cyber Conflict. Retrieved March 10, 2022.

    Open source URL
  16. [16]
    Unit 42 WhisperGate January 2022

    Falcone, R. et al.. (2022, January 20). Threat Brief: Ongoing Russia and Ukraine Cyber Conflict. Retrieved March 10, 2022.

    Open source URL
  17. [17]
    mitre-attackS0689
    Open source URL
  18. [18]
    mitre-attackS0689
    Open source URL
  19. [19]
    mitre-attackS0689
    Open source URL
  20. [20]
    Cisco Ukraine Wipers January 2022

    Biasini, N. et al.. (2022, January 21). Ukraine Campaign Delivers Defacement and Wipers, in Continued Escalation. Retrieved March 14, 2022.

    Open source URL
  21. [21]
    Crowdstrike WhisperGate January 2022

    Crowdstrike. (2022, January 19). Technical Analysis of the WhisperGate Malicious Bootloader. Retrieved March 10, 2022.

    Open source URL
  22. [22]
    Cybereason WhisperGate February 2022

    Cybereason Nocturnus. (2022, February 15). Cybereason vs. WhisperGate and HermeticWiper. Retrieved March 10, 2022.

    Open source URL
  23. [23]
    Cybereason WhisperGate February 2022

    Cybereason Nocturnus. (2022, February 15). Cybereason vs. WhisperGate and HermeticWiper. Retrieved March 10, 2022.

    Open source URL
  24. [24]
    Medium S2W WhisperGate January 2022

    S2W. (2022, January 18). Analysis of Destructive Malware (WhisperGate) targeting Ukraine. Retrieved March 14, 2022.

    Open source URL
  25. [25]
    Microsoft WhisperGate January 2022

    MSTIC. (2022, January 15). Destructive malware targeting Ukrainian organizations. Retrieved March 10, 2022.

    Open source URL
  26. [26]
    Microsoft WhisperGate January 2022

    MSTIC. (2022, January 15). Destructive malware targeting Ukrainian organizations. Retrieved March 10, 2022.

    Open source URL
  27. [27]
    RecordedFuture WhisperGate Jan 2022

    Insikt Group. (2020, January 28). WhisperGate Malware Corrupts Computers in Ukraine. Retrieved September 16, 2024.

    Open source URL
  28. [28]
    Cisco Ukraine Wipers January 2022

    Biasini, N. et al.. (2022, January 21). Ukraine Campaign Delivers Defacement and Wipers, in Continued Escalation. Retrieved March 14, 2022.

    Open source URL
  29. [29]
    Cisco Ukraine Wipers January 2022

    Biasini, N. et al.. (2022, January 21). Ukraine Campaign Delivers Defacement and Wipers, in Continued Escalation. Retrieved March 14, 2022.

    Open source URL
  30. [30]
    Crowdstrike WhisperGate January 2022

    Crowdstrike. (2022, January 19). Technical Analysis of the WhisperGate Malicious Bootloader. Retrieved March 10, 2022.

    Open source URL
  31. [31]
    Crowdstrike WhisperGate January 2022

    Crowdstrike. (2022, January 19). Technical Analysis of the WhisperGate Malicious Bootloader. Retrieved March 10, 2022.

    Open source URL
  32. [32]
    Cybereason WhisperGate February 2022

    Cybereason Nocturnus. (2022, February 15). Cybereason vs. WhisperGate and HermeticWiper. Retrieved March 10, 2022.

    Open source URL
  33. [33]
    Cybereason WhisperGate February 2022

    Cybereason Nocturnus. (2022, February 15). Cybereason vs. WhisperGate and HermeticWiper. Retrieved March 10, 2022.

    Open source URL
  34. [34]
    Medium S2W WhisperGate January 2022

    S2W. (2022, January 18). Analysis of Destructive Malware (WhisperGate) targeting Ukraine. Retrieved March 14, 2022.

    Open source URL
  35. [35]
    Medium S2W WhisperGate January 2022

    S2W. (2022, January 18). Analysis of Destructive Malware (WhisperGate) targeting Ukraine. Retrieved March 14, 2022.

    Open source URL
  36. [36]
    Microsoft WhisperGate January 2022

    MSTIC. (2022, January 15). Destructive malware targeting Ukrainian organizations. Retrieved March 10, 2022.

    Open source URL
  37. [37]
    Microsoft WhisperGate January 2022

    MSTIC. (2022, January 15). Destructive malware targeting Ukrainian organizations. Retrieved March 10, 2022.

    Open source URL
  38. [38]
    Unit 42 WhisperGate January 2022

    Falcone, R. et al.. (2022, January 20). Threat Brief: Ongoing Russia and Ukraine Cyber Conflict. Retrieved March 10, 2022.

    Open source URL
  39. [39]
    Unit 42 WhisperGate January 2022

    Falcone, R. et al.. (2022, January 20). Threat Brief: Ongoing Russia and Ukraine Cyber Conflict. Retrieved March 10, 2022.

    Open source URL
  40. [40]
    Cisco Ukraine Wipers January 2022

    Biasini, N. et al.. (2022, January 21). Ukraine Campaign Delivers Defacement and Wipers, in Continued Escalation. Retrieved March 14, 2022.

    Open source URL
  41. [41]
    Cisco Ukraine Wipers January 2022

    Biasini, N. et al.. (2022, January 21). Ukraine Campaign Delivers Defacement and Wipers, in Continued Escalation. Retrieved March 14, 2022.

    Open source URL
  42. [42]
    Medium S2W WhisperGate January 2022

    S2W. (2022, January 18). Analysis of Destructive Malware (WhisperGate) targeting Ukraine. Retrieved March 14, 2022.

    Open source URL
  43. [43]
    Medium S2W WhisperGate January 2022

    S2W. (2022, January 18). Analysis of Destructive Malware (WhisperGate) targeting Ukraine. Retrieved March 14, 2022.

    Open source URL
  44. [44]
    Unit 42 WhisperGate January 2022

    Falcone, R. et al.. (2022, January 20). Threat Brief: Ongoing Russia and Ukraine Cyber Conflict. Retrieved March 10, 2022.

    Open source URL
  45. [45]
    Unit 42 WhisperGate January 2022

    Falcone, R. et al.. (2022, January 20). Threat Brief: Ongoing Russia and Ukraine Cyber Conflict. Retrieved March 10, 2022.

    Open source URL
  46. [46]
    Cisco Ukraine Wipers January 2022

    Biasini, N. et al.. (2022, January 21). Ukraine Campaign Delivers Defacement and Wipers, in Continued Escalation. Retrieved March 14, 2022.

    Open source URL
  47. [47]
    Cisco Ukraine Wipers January 2022

    Biasini, N. et al.. (2022, January 21). Ukraine Campaign Delivers Defacement and Wipers, in Continued Escalation. Retrieved March 14, 2022.

    Open source URL
  48. [48]
    Medium S2W WhisperGate January 2022

    S2W. (2022, January 18). Analysis of Destructive Malware (WhisperGate) targeting Ukraine. Retrieved March 14, 2022.

    Open source URL
  49. [49]
    Medium S2W WhisperGate January 2022

    S2W. (2022, January 18). Analysis of Destructive Malware (WhisperGate) targeting Ukraine. Retrieved March 14, 2022.

    Open source URL
  50. [50]
    Microsoft WhisperGate January 2022

    MSTIC. (2022, January 15). Destructive malware targeting Ukrainian organizations. Retrieved March 10, 2022.

    Open source URL
  51. [51]
    Microsoft WhisperGate January 2022

    MSTIC. (2022, January 15). Destructive malware targeting Ukrainian organizations. Retrieved March 10, 2022.

    Open source URL
  52. [52]
    Unit 42 WhisperGate January 2022

    Falcone, R. et al.. (2022, January 20). Threat Brief: Ongoing Russia and Ukraine Cyber Conflict. Retrieved March 10, 2022.

    Open source URL
  53. [53]
    Unit 42 WhisperGate January 2022

    Falcone, R. et al.. (2022, January 20). Threat Brief: Ongoing Russia and Ukraine Cyber Conflict. Retrieved March 10, 2022.

    Open source URL
  54. [54]
    Cisco Ukraine Wipers January 2022

    Biasini, N. et al.. (2022, January 21). Ukraine Campaign Delivers Defacement and Wipers, in Continued Escalation. Retrieved March 14, 2022.

    Open source URL
  55. [55]
    Cisco Ukraine Wipers January 2022

    Biasini, N. et al.. (2022, January 21). Ukraine Campaign Delivers Defacement and Wipers, in Continued Escalation. Retrieved March 14, 2022.

    Open source URL
  56. [56]
    Medium S2W WhisperGate January 2022

    S2W. (2022, January 18). Analysis of Destructive Malware (WhisperGate) targeting Ukraine. Retrieved March 14, 2022.

    Open source URL
  57. [57]
    Medium S2W WhisperGate January 2022

    S2W. (2022, January 18). Analysis of Destructive Malware (WhisperGate) targeting Ukraine. Retrieved March 14, 2022.

    Open source URL
  58. [58]
    Unit 42 WhisperGate January 2022

    Falcone, R. et al.. (2022, January 20). Threat Brief: Ongoing Russia and Ukraine Cyber Conflict. Retrieved March 10, 2022.

    Open source URL
  59. [59]
    Unit 42 WhisperGate January 2022

    Falcone, R. et al.. (2022, January 20). Threat Brief: Ongoing Russia and Ukraine Cyber Conflict. Retrieved March 10, 2022.

    Open source URL
  60. [60]
    Unit 42 WhisperGate January 2022

    Falcone, R. et al.. (2022, January 20). Threat Brief: Ongoing Russia and Ukraine Cyber Conflict. Retrieved March 10, 2022.

    Open source URL
  61. [61]
    Unit 42 WhisperGate January 2022

    Falcone, R. et al.. (2022, January 20). Threat Brief: Ongoing Russia and Ukraine Cyber Conflict. Retrieved March 10, 2022.

    Open source URL
  62. [62]
    Cisco Ukraine Wipers January 2022

    Biasini, N. et al.. (2022, January 21). Ukraine Campaign Delivers Defacement and Wipers, in Continued Escalation. Retrieved March 14, 2022.

    Open source URL
  63. [63]
    Cisco Ukraine Wipers January 2022

    Biasini, N. et al.. (2022, January 21). Ukraine Campaign Delivers Defacement and Wipers, in Continued Escalation. Retrieved March 14, 2022.

    Open source URL
  64. [64]
    Medium S2W WhisperGate January 2022

    S2W. (2022, January 18). Analysis of Destructive Malware (WhisperGate) targeting Ukraine. Retrieved March 14, 2022.

    Open source URL
  65. [65]
    Medium S2W WhisperGate January 2022

    S2W. (2022, January 18). Analysis of Destructive Malware (WhisperGate) targeting Ukraine. Retrieved March 14, 2022.

    Open source URL
  66. [66]
    RecordedFuture WhisperGate Jan 2022

    Insikt Group. (2020, January 28). WhisperGate Malware Corrupts Computers in Ukraine. Retrieved September 16, 2024.

    Open source URL
  67. [67]
    RecordedFuture WhisperGate Jan 2022

    Insikt Group. (2020, January 28). WhisperGate Malware Corrupts Computers in Ukraine. Retrieved September 16, 2024.

    Open source URL
  68. [68]
    Cisco Ukraine Wipers January 2022

    Biasini, N. et al.. (2022, January 21). Ukraine Campaign Delivers Defacement and Wipers, in Continued Escalation. Retrieved March 14, 2022.

    Open source URL
  69. [69]
    Cisco Ukraine Wipers January 2022

    Biasini, N. et al.. (2022, January 21). Ukraine Campaign Delivers Defacement and Wipers, in Continued Escalation. Retrieved March 14, 2022.

    Open source URL
  70. [70]
    RecordedFuture WhisperGate Jan 2022

    Insikt Group. (2020, January 28). WhisperGate Malware Corrupts Computers in Ukraine. Retrieved September 16, 2024.

    Open source URL
  71. [71]
    RecordedFuture WhisperGate Jan 2022

    Insikt Group. (2020, January 28). WhisperGate Malware Corrupts Computers in Ukraine. Retrieved September 16, 2024.

    Open source URL
  72. [72]
    Medium S2W WhisperGate January 2022

    S2W. (2022, January 18). Analysis of Destructive Malware (WhisperGate) targeting Ukraine. Retrieved March 14, 2022.

    Open source URL
  73. [73]
    Medium S2W WhisperGate January 2022

    S2W. (2022, January 18). Analysis of Destructive Malware (WhisperGate) targeting Ukraine. Retrieved March 14, 2022.

    Open source URL
  74. [74]
    Unit 42 WhisperGate January 2022

    Falcone, R. et al.. (2022, January 20). Threat Brief: Ongoing Russia and Ukraine Cyber Conflict. Retrieved March 10, 2022.

    Open source URL
  75. [75]
    Unit 42 WhisperGate January 2022

    Falcone, R. et al.. (2022, January 20). Threat Brief: Ongoing Russia and Ukraine Cyber Conflict. Retrieved March 10, 2022.

    Open source URL
  76. [76]
    Cisco Ukraine Wipers January 2022

    Biasini, N. et al.. (2022, January 21). Ukraine Campaign Delivers Defacement and Wipers, in Continued Escalation. Retrieved March 14, 2022.

    Open source URL
  77. [77]
    Cisco Ukraine Wipers January 2022

    Biasini, N. et al.. (2022, January 21). Ukraine Campaign Delivers Defacement and Wipers, in Continued Escalation. Retrieved March 14, 2022.

    Open source URL
  78. [78]
    Cisco Ukraine Wipers January 2022

    Biasini, N. et al.. (2022, January 21). Ukraine Campaign Delivers Defacement and Wipers, in Continued Escalation. Retrieved March 14, 2022.

    Open source URL
  79. [79]
    Cisco Ukraine Wipers January 2022

    Biasini, N. et al.. (2022, January 21). Ukraine Campaign Delivers Defacement and Wipers, in Continued Escalation. Retrieved March 14, 2022.

    Open source URL
  80. [80]
    Crowdstrike WhisperGate January 2022

    Crowdstrike. (2022, January 19). Technical Analysis of the WhisperGate Malicious Bootloader. Retrieved March 10, 2022.

    Open source URL
  81. [81]
    Crowdstrike WhisperGate January 2022

    Crowdstrike. (2022, January 19). Technical Analysis of the WhisperGate Malicious Bootloader. Retrieved March 10, 2022.

    Open source URL
  82. [82]
    Cybereason WhisperGate February 2022

    Cybereason Nocturnus. (2022, February 15). Cybereason vs. WhisperGate and HermeticWiper. Retrieved March 10, 2022.

    Open source URL
  83. [83]
    Cybereason WhisperGate February 2022

    Cybereason Nocturnus. (2022, February 15). Cybereason vs. WhisperGate and HermeticWiper. Retrieved March 10, 2022.

    Open source URL
  84. [84]
    Medium S2W WhisperGate January 2022

    S2W. (2022, January 18). Analysis of Destructive Malware (WhisperGate) targeting Ukraine. Retrieved March 14, 2022.

    Open source URL
  85. [85]
    Medium S2W WhisperGate January 2022

    S2W. (2022, January 18). Analysis of Destructive Malware (WhisperGate) targeting Ukraine. Retrieved March 14, 2022.

    Open source URL
  86. [86]
    Microsoft WhisperGate January 2022

    MSTIC. (2022, January 15). Destructive malware targeting Ukrainian organizations. Retrieved March 10, 2022.

    Open source URL
  87. [87]
    Microsoft WhisperGate January 2022

    MSTIC. (2022, January 15). Destructive malware targeting Ukrainian organizations. Retrieved March 10, 2022.

    Open source URL
  88. [88]
    Unit 42 WhisperGate January 2022

    Falcone, R. et al.. (2022, January 20). Threat Brief: Ongoing Russia and Ukraine Cyber Conflict. Retrieved March 10, 2022.

    Open source URL
  89. [89]
    Unit 42 WhisperGate January 2022

    Falcone, R. et al.. (2022, January 20). Threat Brief: Ongoing Russia and Ukraine Cyber Conflict. Retrieved March 10, 2022.

    Open source URL
  90. [90]
    Cisco Ukraine Wipers January 2022

    Biasini, N. et al.. (2022, January 21). Ukraine Campaign Delivers Defacement and Wipers, in Continued Escalation. Retrieved March 14, 2022.

    Open source URL
  91. [91]
    Cisco Ukraine Wipers January 2022

    Biasini, N. et al.. (2022, January 21). Ukraine Campaign Delivers Defacement and Wipers, in Continued Escalation. Retrieved March 14, 2022.

    Open source URL
  92. [92]
    Crowdstrike WhisperGate January 2022

    Crowdstrike. (2022, January 19). Technical Analysis of the WhisperGate Malicious Bootloader. Retrieved March 10, 2022.

    Open source URL
  93. [93]
    Crowdstrike WhisperGate January 2022

    Crowdstrike. (2022, January 19). Technical Analysis of the WhisperGate Malicious Bootloader. Retrieved March 10, 2022.

    Open source URL
  94. [94]
    Medium S2W WhisperGate January 2022

    S2W. (2022, January 18). Analysis of Destructive Malware (WhisperGate) targeting Ukraine. Retrieved March 14, 2022.

    Open source URL
  95. [95]
    Medium S2W WhisperGate January 2022

    S2W. (2022, January 18). Analysis of Destructive Malware (WhisperGate) targeting Ukraine. Retrieved March 14, 2022.

    Open source URL
  96. [96]
    Unit 42 WhisperGate January 2022

    Falcone, R. et al.. (2022, January 20). Threat Brief: Ongoing Russia and Ukraine Cyber Conflict. Retrieved March 10, 2022.

    Open source URL
  97. [97]
    Unit 42 WhisperGate January 2022

    Falcone, R. et al.. (2022, January 20). Threat Brief: Ongoing Russia and Ukraine Cyber Conflict. Retrieved March 10, 2022.

    Open source URL
  98. [98]
    Unit 42 WhisperGate January 2022

    Falcone, R. et al.. (2022, January 20). Threat Brief: Ongoing Russia and Ukraine Cyber Conflict. Retrieved March 10, 2022.

    Open source URL
  99. [99]
    Unit 42 WhisperGate January 2022

    Falcone, R. et al.. (2022, January 20). Threat Brief: Ongoing Russia and Ukraine Cyber Conflict. Retrieved March 10, 2022.

    Open source URL
  100. [100]
    Cisco Ukraine Wipers January 2022

    Biasini, N. et al.. (2022, January 21). Ukraine Campaign Delivers Defacement and Wipers, in Continued Escalation. Retrieved March 14, 2022.

    Open source URL
  101. [101]
    Cisco Ukraine Wipers January 2022

    Biasini, N. et al.. (2022, January 21). Ukraine Campaign Delivers Defacement and Wipers, in Continued Escalation. Retrieved March 14, 2022.

    Open source URL
  102. [102]
    Medium S2W WhisperGate January 2022

    S2W. (2022, January 18). Analysis of Destructive Malware (WhisperGate) targeting Ukraine. Retrieved March 14, 2022.

    Open source URL
  103. [103]
    Medium S2W WhisperGate January 2022

    S2W. (2022, January 18). Analysis of Destructive Malware (WhisperGate) targeting Ukraine. Retrieved March 14, 2022.

    Open source URL
  104. [104]
    Unit 42 WhisperGate January 2022

    Falcone, R. et al.. (2022, January 20). Threat Brief: Ongoing Russia and Ukraine Cyber Conflict. Retrieved March 10, 2022.

    Open source URL
  105. [105]
    Unit 42 WhisperGate January 2022

    Falcone, R. et al.. (2022, January 20). Threat Brief: Ongoing Russia and Ukraine Cyber Conflict. Retrieved March 10, 2022.

    Open source URL
  106. [106]
    Cisco Ukraine Wipers January 2022

    Biasini, N. et al.. (2022, January 21). Ukraine Campaign Delivers Defacement and Wipers, in Continued Escalation. Retrieved March 14, 2022.

    Open source URL
  107. [107]
    Cisco Ukraine Wipers January 2022

    Biasini, N. et al.. (2022, January 21). Ukraine Campaign Delivers Defacement and Wipers, in Continued Escalation. Retrieved March 14, 2022.

    Open source URL
  108. [108]
    Cisco Ukraine Wipers January 2022

    Biasini, N. et al.. (2022, January 21). Ukraine Campaign Delivers Defacement and Wipers, in Continued Escalation. Retrieved March 14, 2022.

    Open source URL
  109. [109]
    Cisco Ukraine Wipers January 2022

    Biasini, N. et al.. (2022, January 21). Ukraine Campaign Delivers Defacement and Wipers, in Continued Escalation. Retrieved March 14, 2022.

    Open source URL
  110. [110]
    RecordedFuture WhisperGate Jan 2022

    Insikt Group. (2020, January 28). WhisperGate Malware Corrupts Computers in Ukraine. Retrieved September 16, 2024.

    Open source URL
  111. [111]
    RecordedFuture WhisperGate Jan 2022

    Insikt Group. (2020, January 28). WhisperGate Malware Corrupts Computers in Ukraine. Retrieved September 16, 2024.

    Open source URL
  112. [112]
    Cadet Blizzard emerges as novel threat actor

    Microsoft Threat Intelligence. (2023, June 14). Cadet Blizzard emerges as a novel and distinct Russian threat actor. Retrieved July 10, 2023.

    Open source URL
  113. [113]
    CrowdStrike Ember Bear Profile March 2022

    CrowdStrike. (2022, March 30). Who is EMBER BEAR?. Retrieved June 9, 2022.

    Open source URL
  114. [114]
    Mandiant UNC2589 March 2022

    Sadowski, J; Hall, R. (2022, March 4). Responses to Russia's Invasion of Ukraine Likely to Spur Retaliation. Retrieved June 9, 2022.

    Open source URL
  115. [115]
    Unit 42 WhisperGate January 2022

    Falcone, R. et al.. (2022, January 20). Threat Brief: Ongoing Russia and Ukraine Cyber Conflict. Retrieved March 10, 2022.

    Open source URL
  116. [116]
    Unit 42 WhisperGate January 2022

    Falcone, R. et al.. (2022, January 20). Threat Brief: Ongoing Russia and Ukraine Cyber Conflict. Retrieved March 10, 2022.

    Open source URL
  117. [117]
    Cisco Ukraine Wipers January 2022

    Biasini, N. et al.. (2022, January 21). Ukraine Campaign Delivers Defacement and Wipers, in Continued Escalation. Retrieved March 14, 2022.

    Open source URL
  118. [118]
    Cisco Ukraine Wipers January 2022

    Biasini, N. et al.. (2022, January 21). Ukraine Campaign Delivers Defacement and Wipers, in Continued Escalation. Retrieved March 14, 2022.

    Open source URL
  119. [119]
    Unit 42 WhisperGate January 2022

    Falcone, R. et al.. (2022, January 20). Threat Brief: Ongoing Russia and Ukraine Cyber Conflict. Retrieved March 10, 2022.

    Open source URL
  120. [120]
    Unit 42 WhisperGate January 2022

    Falcone, R. et al.. (2022, January 20). Threat Brief: Ongoing Russia and Ukraine Cyber Conflict. Retrieved March 10, 2022.

    Open source URL
  121. [121]
    Cisco Ukraine Wipers January 2022

    Biasini, N. et al.. (2022, January 21). Ukraine Campaign Delivers Defacement and Wipers, in Continued Escalation. Retrieved March 14, 2022.

    Open source URL
  122. [122]
    Cisco Ukraine Wipers January 2022

    Biasini, N. et al.. (2022, January 21). Ukraine Campaign Delivers Defacement and Wipers, in Continued Escalation. Retrieved March 14, 2022.

    Open source URL
  123. [123]
    Cisco Ukraine Wipers January 2022

    Biasini, N. et al.. (2022, January 21). Ukraine Campaign Delivers Defacement and Wipers, in Continued Escalation. Retrieved March 14, 2022.

    Open source URL
  124. [124]
    Cisco Ukraine Wipers January 2022

    Biasini, N. et al.. (2022, January 21). Ukraine Campaign Delivers Defacement and Wipers, in Continued Escalation. Retrieved March 14, 2022.

    Open source URL
  125. [125]
    Crowdstrike WhisperGate January 2022

    Crowdstrike. (2022, January 19). Technical Analysis of the WhisperGate Malicious Bootloader. Retrieved March 10, 2022.

    Open source URL
  126. [126]
    Crowdstrike WhisperGate January 2022

    Crowdstrike. (2022, January 19). Technical Analysis of the WhisperGate Malicious Bootloader. Retrieved March 10, 2022.

    Open source URL
  127. [127]
    Medium S2W WhisperGate January 2022

    S2W. (2022, January 18). Analysis of Destructive Malware (WhisperGate) targeting Ukraine. Retrieved March 14, 2022.

    Open source URL
  128. [128]
    Medium S2W WhisperGate January 2022

    S2W. (2022, January 18). Analysis of Destructive Malware (WhisperGate) targeting Ukraine. Retrieved March 14, 2022.

    Open source URL
  129. [129]
    Microsoft WhisperGate January 2022

    MSTIC. (2022, January 15). Destructive malware targeting Ukrainian organizations. Retrieved March 10, 2022.

    Open source URL
  130. [130]
    Microsoft WhisperGate January 2022

    MSTIC. (2022, January 15). Destructive malware targeting Ukrainian organizations. Retrieved March 10, 2022.

    Open source URL
  131. [131]
    Unit 42 WhisperGate January 2022

    Falcone, R. et al.. (2022, January 20). Threat Brief: Ongoing Russia and Ukraine Cyber Conflict. Retrieved March 10, 2022.

    Open source URL
  132. [132]
    Unit 42 WhisperGate January 2022

    Falcone, R. et al.. (2022, January 20). Threat Brief: Ongoing Russia and Ukraine Cyber Conflict. Retrieved March 10, 2022.

    Open source URL
  133. [133]
    Cisco Ukraine Wipers January 2022

    Biasini, N. et al.. (2022, January 21). Ukraine Campaign Delivers Defacement and Wipers, in Continued Escalation. Retrieved March 14, 2022.

    Open source URL
  134. [134]
    Cisco Ukraine Wipers January 2022

    Biasini, N. et al.. (2022, January 21). Ukraine Campaign Delivers Defacement and Wipers, in Continued Escalation. Retrieved March 14, 2022.

    Open source URL
  135. [135]
    Medium S2W WhisperGate January 2022

    S2W. (2022, January 18). Analysis of Destructive Malware (WhisperGate) targeting Ukraine. Retrieved March 14, 2022.

    Open source URL
  136. [136]
    Medium S2W WhisperGate January 2022

    S2W. (2022, January 18). Analysis of Destructive Malware (WhisperGate) targeting Ukraine. Retrieved March 14, 2022.

    Open source URL
  137. [137]
    RecordedFuture WhisperGate Jan 2022

    Insikt Group. (2020, January 28). WhisperGate Malware Corrupts Computers in Ukraine. Retrieved September 16, 2024.

    Open source URL
  138. [138]
    RecordedFuture WhisperGate Jan 2022

    Insikt Group. (2020, January 28). WhisperGate Malware Corrupts Computers in Ukraine. Retrieved September 16, 2024.

    Open source URL
  139. [139]
    Cisco Ukraine Wipers January 2022

    Biasini, N. et al.. (2022, January 21). Ukraine Campaign Delivers Defacement and Wipers, in Continued Escalation. Retrieved March 14, 2022.

    Open source URL
  140. [140]
    Cisco Ukraine Wipers January 2022

    Biasini, N. et al.. (2022, January 21). Ukraine Campaign Delivers Defacement and Wipers, in Continued Escalation. Retrieved March 14, 2022.

    Open source URL
  141. [141]
    Medium S2W WhisperGate January 2022

    S2W. (2022, January 18). Analysis of Destructive Malware (WhisperGate) targeting Ukraine. Retrieved March 14, 2022.

    Open source URL
  142. [142]
    Medium S2W WhisperGate January 2022

    S2W. (2022, January 18). Analysis of Destructive Malware (WhisperGate) targeting Ukraine. Retrieved March 14, 2022.

    Open source URL
  143. [143]
    Medium S2W WhisperGate January 2022

    S2W. (2022, January 18). Analysis of Destructive Malware (WhisperGate) targeting Ukraine. Retrieved March 14, 2022.

    Open source URL
  144. [144]
    Medium S2W WhisperGate January 2022

    S2W. (2022, January 18). Analysis of Destructive Malware (WhisperGate) targeting Ukraine. Retrieved March 14, 2022.

    Open source URL
  145. [145]
    Cisco Ukraine Wipers January 2022

    Biasini, N. et al.. (2022, January 21). Ukraine Campaign Delivers Defacement and Wipers, in Continued Escalation. Retrieved March 14, 2022.

    Open source URL
  146. [146]
    Medium S2W WhisperGate January 2022

    S2W. (2022, January 18). Analysis of Destructive Malware (WhisperGate) targeting Ukraine. Retrieved March 14, 2022.

    Open source URL
  147. [147]
    Microsoft WhisperGate January 2022

    MSTIC. (2022, January 15). Destructive malware targeting Ukrainian organizations. Retrieved March 10, 2022.

    Open source URL
  148. [148]
    Unit 42 WhisperGate January 2022

    Falcone, R. et al.. (2022, January 20). Threat Brief: Ongoing Russia and Ukraine Cyber Conflict. Retrieved March 10, 2022.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.