{"id":8268,"date":"2025-11-07T10:05:19","date_gmt":"2025-11-07T10:05:19","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/11\/07\/sandworm-hackers-attacking-ukranian-organizations-with-data-wiper-malwares\/"},"modified":"2025-11-07T10:05:19","modified_gmt":"2025-11-07T10:05:19","slug":"sandworm-hackers-attacking-ukranian-organizations-with-data-wiper-malwares","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/11\/07\/sandworm-hackers-attacking-ukranian-organizations-with-data-wiper-malwares\/","title":{"rendered":"Sandworm Hackers Attacking Ukranian Organizations with Data Wiper Malwares"},"content":{"rendered":"<p>    Sandworm Hackers Attacking Ukranian Organizations with Data Wiper Malwares<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>The Russia-aligned Sandworm threat group has intensified its destructive cyberattacks against Ukrainian organizations, deploying sophisticated data wiper malware designed to cripple critical infrastructure and economic operations.<\/p>\n<p>Unlike traditional cyberespionage campaigns, Sandworm\u2019s recent operations focus exclusively on destruction, targeting governmental entities, energy providers, logistics companies, and the grain sector with malicious tools named ZEROLOT and Sting.<\/p>\n<p>These attacks aim to weaken Ukraine\u2019s economic stability during an ongoing geopolitical conflict, demonstrating the group\u2019s strategic shift from intelligence gathering to causing maximum disruption.<\/p>\n<p>The campaign specifically targets critical sectors vital to Ukraine\u2019s economy and national security.<\/p>\n<p>The threat actor has concentrated efforts on governmental organizations responsible for administrative functions, energy companies managing power infrastructure, logistics operations supporting supply chains, and agricultural entities within the grain sector.<\/p>\n<p>Welivesecurity security researchers <a href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/eset-apt-activity-report-q2-2025-q3-2025\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> this coordinated assault as part of Sandworm\u2019s broader strategy to destabilize Ukrainian operations through permanent data loss.<\/p>\n<p>The deployment of data wipers represents a dangerous escalation in <a href=\"https:\/\/cybersecuritynews.com\/cyber-warfare\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">cyber warfare<\/a> tactics, as these tools are designed to render systems completely inoperable by permanently erasing data and corrupting file systems.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjeQEFDpd7L0SjQkkgp_bbS8L7p4gnzZgl4f_T2iPiddG1WcBqgPCY3Fntg9deg59HHEQ3Mycrdtnsk3-NvdZZXtvrqULrlQXLlgr3SeWPiQx-A_AQVIwftVgjY8EiEOjX1imhBS2Yr_6LEisjiH2V_yP0TB6Yq4dxtZq9IPGzG2wkkyno1lX4x3guL93w\/s16000\/Targeted%2520countries%2520and%2520sectors%2520%28Source%2520-%2520Welivesecurity%29.webp?ssl=1\" alt=\"Targeted countries and sectors (Source - Welivesecurity)\"><figcaption class=\"wp-element-caption\">Targeted countries and sectors (Source \u2013 Welivesecurity)<\/figcaption><\/figure>\n<\/div>\n<p>The malware operates by exploiting vulnerabilities in target networks through <a href=\"https:\/\/cybersecuritynews.com\/new-phishing-attack-via-onedrive-attacking-c-level-employees\/\" target=\"_blank\" rel=\"noreferrer noopener\">spearphishing<\/a> campaigns and compromised credentials.<\/p>\n<p>Once inside the network, ZEROLOT and Sting execute destructive routines that overwrite critical system files, partition tables, and stored data with random values, making recovery virtually impossible without offline backups.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-wiper-deployment\"><strong>Wiper Deployment<\/strong><\/h2>\n<p>The data wipers employ advanced techniques to maximize damage before detection.<\/p>\n<p>ZEROLOT specifically targets Master Boot Records and file allocation tables, ensuring that operating systems cannot boot after the attack completes.<\/p>\n<p>The malware includes anti-forensic capabilities that delete event logs and system restore points, eliminating evidence of the intrusion.<\/p>\n<p>Sting operates with elevated privileges obtained through credential theft and <a href=\"https:\/\/cybersecuritynews.com\/cisa-windows-privilege-escalation-vulnerability\/\">privilege escalation<\/a> exploits, allowing unrestricted access to protected system areas.<\/p>\n<p>Both wipers incorporate timing mechanisms that delay execution until achieving maximum network propagation, ensuring widespread impact across connected infrastructure before security teams can respond effectively to the threat.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/sandworm-hackers-attacking-ukranian-organizations\/\">Sandworm Hackers Attacking Ukranian Organizations with Data Wiper Malwares<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/sandworm-hackers-attacking-ukranian-organizations\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Sandworm Hackers Attacking Ukranian Organizations with Data Wiper Malwares The Russia-aligned Sandworm threat group has intensified its destructive cyberattacks against Ukrainian organizations, deploying sophisticated data wiper malware designed to cripple critical infrastructure and economic operations. Unlike traditional cyberespionage campaigns, Sandworm\u2019s recent operations focus exclusively on destruction, targeting governmental entities, energy providers, logistics companies, and the [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-8268","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8268"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=8268"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8268\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=8268"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=8268"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=8268"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}