ESET researchers have recently uncovered that the notorious Sandworm APT group has added a new wiper malware to its hacking toolkit. The wiper is based on a command-line utility from Microsoft called SDelete, which is used for securely deleting files. This wiper was used in an attack on a Ukrainian energy sector company in October 2022. In addition to the wiper, the group was also observed to be deploying malicious software such as ransomware. Unlike typical ransomware attacks, these attacks aim to completely destroy the data without any possibility of recovery. ESET researchers also discovered that the group was using POWERGAP scripts to deploy the ransomware, as well as Active Directory Group Policy to distribute its wiper and ransomware payloads. The group was also observed to be involved in spearphishing activities, with the goal of acquiring webmail credentials. Security experts have warned that the Sandworm group remains a significant risk for Ukrainian institutions.
This Cyber News was published on cybersecuritynews.com. Publication date: Thu, 02 Feb 2023 07:58:03 +0000