/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Microsoft identifies a destructive malware operation targeting Ukrainian organizations; the malware looks like ransomware but lacks a ransom recovery mechanism

European Union simulated a cyber attack on a fictitious Finnish power company Vilius Petkauskas / cybernews.com : Belarus state hackers suspected behind Ukraine cyberattack Grugq / grugq's domain : Ukraine my heart, cyber just for show? Jonathan Greig / ZDNet : Microsoft says ‘destructive malware’ being used against Ukrainian organizations Benzinga : Microsoft Warns Ukrainian Government Computer Systems Infected; Security Official Suspects Russian Intelligence Graham Cluley : Data-wiping malware hitting Ukrainian computers displays fake ransom demand Michael Novinson / CRN : Microsoft: Ukrainian Government Hit With Destructive Malware Nathaniel Mott / PCMag : Microsoft: Ukrainian Companies Are Being Targeted by Destructive Malware Mike Lennon / SecurityWeek : Microsoft Uncovers Destructive Malware Used in Ukraine Cyberattacks The Moscow Times : Ukraine Says Has ‘Evidence’ Russia Behind Cyberattack Surur / MSPoweruser : Microsoft assisting Ukrainian government in fighting off Russian cyber-attack CISA : Microsoft Warns of Destructive Malware Targeting Ukrainian Organizations Mychael Schnell / The Hill : Ukraine government agencies' computer systems infected with malware, Microsoft says ANI / Livemint : Microsoft warns of destructive malware in computer systems of Ukrainian state institutions Catalin Cimpanu / The Record : Microsoft: Data-wiping malware disguised as ransomware targets Ukraine again Ravie Lakshmanan / The Hacker News : A New Destructive Malware Targeting Ukrainian Government and Business Entities Anirudh Saligrama / Reuters : Microsoft says it observed destructive malware in systems belonging to several Ukraine govt agencies Eduard Gismatullin / Bloomberg : Microsoft Finds Destructive Malware in Attacks Targeting Ukraine Tweets: @msftsecintel : Microsoft identified a unique destructive malware operated by an actor tracked as DEV-0586 targeting Ukrainian organizations. Observed activity, TTPs, and IOCs shared in this new MSTIC blog. We'll update the blog as our investigation unfolds. https://www.microsoft.com/... @uscert_gov : ⚠️ @CISAgov recommends network defenders review the Microsoft blog on destructive malware targeting Ukrainian organizations. https://www.cisa.gov/... #Cybersecurity #InfoSec Andy Greenberg / @a_greenberg : A new round of data-destroying fake ransomware attacks in Ukraine appears to be small-scale for now. But it's uncomfortably similar to Russia's escalating attacks from 2015-2017 that culminated in NotPetya's $10 billion devastation. https://www.wired.com/... Nick Carr / @itsreallynick : When our awesome #MSTIC Russia team discovered this event unfolding in real-time 🤯, here was our crime triage on how DEV-0586's destructive malware differs from 𝘵𝘺𝘱𝘪 𝘤𝘢𝘭 human-operated ransomware. “Ransom” note in the blog: https://www.microsoft.com/... - anything we missed? https://twitter.com/... https://twitter.com/... @pa : Ukraine says Russia was behind a cyberattack that defaced government websites and it alleged that Russia is engaged in a “hybrid war” against the country https://www.independent.co.uk/ ... Jared Cohen / @jaredcohen : In 2022, all wars will begin as cyberwars. Whether a physical front of a war opens is just a question of scale. #ukraine is the first major case study in the new year: https://www.nytimes.com/... Shannon Bray / @shannonbraync : Microsoft is sharing this information to help others in the cybersecurity community look out for and defend against these attacks. https://blogs.microsoft.com/ ... Crispin Burke / @crispinburke : Ukrainian authorities suspect a Belarus-based hacking group known as UNC1151, or “Ghostwriter”, defaced several Ukrainian government websites. Ukrainian intelligence also believes the campaign was a cover for more sophisticated cyber activity. https://www.reuters.com/... Katie Nickels / @likethecoins : A simple threat modeling exercise. You/your leadership may be focused on the destructive attacks in Ukraine: https://www.microsoft.com/.... But if you're not in Ukraine, I'd argue threats against VMware Horizon should likely be a higher priority: https://www.huntress.com/.... Ciaran Martin / @ciaranmartinoxf : “It was unclear if the defacement was related to the far more destructive code that Microsoft said it had detected.” from ⁦@nytimes⁩ Anyone seen anything definitive on whether the defacements are or aren't connected to the more destructive stuff? https://www.nytimes.com/... William Turton / @williamturton : Feels like we've witnessed a very familiar cycle again here something cyber happens > media reacts > people on twitter scold others for overreacting > a few days later it turns out to be a bigger deal than we knew https://twitter.com/... @fsecure : .@c_gcw's thoughts on the destructive malware targeting organizations in Ukraine. Malware info >> https://www.microsoft.com/... https://twitter.com/... @ffforward : File with similar basic behavior uploaded from UA as “Crypted.exe” on the 14th: https://www.virustotal.com/... Needs to be run from %temp% as Stage1.exe, however I'm only getting a loop of Stage1 > Stage2 > Stage1 etc and no traffic, so no confirmation it's the real thing. https://twitter.com/... @r00tbsd : There is similar samples on VT... Are they related to the incident? If yes, why did you make the choice to put hashes from samples not on VT in the blog post? #SharingIsCaring https://twitter.com/... Christopher Miller / @christopherjm : .@Microsoft findings back up my reporting of an uptick in malware targeting systems of Ukrainian government agencies and organizations: https://blogs.microsoft.com/ ... See my reporting here: https://twitter.com/... @bushidotoken : “Upon execution, stage2.exe downloads the next-stage malware hosted on a Discord channel, with the download link hardcoded in the downloader” Once again, @discord CDN is supporting malware distribution, this time a destructive MBR wiper attack against Ukrainian government orgs https://twitter.com/... Carl Bildt / @carlbildt : This is serious! It looks as if what was immediately seen of the cyberattack against 🇺🇦 was just there to insert malware that under instruction at some time would more or less destroy all the systems. https://twitter.com/... @andersostlund : Serious question: When does a cyber attack become an act of war? The answer will have a great impact on how the alliance approach Russia now, if indeed it was Russia who launched the attack. https://twitter.com/... Rem Korteweg / @remkorteweg : Looks like Friday's cyberattack on UKR sites may have been cover to insert “destructive malware” which - if activated - could weaken, or knock out, Ukrainian command & control. https://twitter.com/... @ilvestoomas : Now *this*, as opposed to homepage defacing, is a cyber attack. https://www.microsoft.com/... @totalforsvar : Kyiv believes a hacker group linked to Belarusian intelligence carried out a cyberattack that hit Ukrainian government websites this week and used malware similar to that used by a group tied to Russian intelligence. https://www.reuters.com/... David Sanger / @sangernyt : There's a playbook to all this - one the private sector can sometimes see faster than the govt. can, or the intended victims. https://www.nytimes.com/... Bryan MacDonald / @27khv : Interesting, to say the least: Friday's cyberattack targeting Ukrainian government agencies was carried out by a group linked to Belarusian intelligence services - and not by Russians, as originally claimed - according to a senior Kiev security official. https://www.rt.com/... @mikko : Reflections of the 2017 Notpetya attack against Ukraine. “The malware, which is designed to look like ransomware but lacking a ransom recovery mechanism, is intended to be destructive and designed to render targeted devices inoperable rather than to obtain a ransom...” https://twitter.com/... Mike Eckel / @mike_eckel : here's what Microsoft says it's found about the malware hack/attack on Ukrainian government websites ( short version: it's bigger than realized; it's not the last of its kind, it's not a criminal group, but rather a state-sponsored agency): https://www.microsoft.com/... https://twitter.com/... Chris Krebs / @c_c_krebs : The other shoe drops on the comment made by Ukrainian official about behind the scenes destructive attacks. Good work here by @MSTIC. Who could it be? https://twitter.com/... https://twitter.com/... @netspooky : Lol remember when I referred to Discord as a “popular malware hosting platform” and people were like “wait what are you talking about?” after years of already being like “hrmmm maybe something should be done about this”? The CyberWar remembers. https://www.microsoft.com/... https://twitter.com/... https://twitter.com/... Sean Lyngaas / @snlyngaas : Microsoft “assesses that the malware, which is designed to look like ransomware but lacking a ransom recovery mechanism, is intended to be destructive and designed to render targeted devices inoperable rather than to obtain a ransom.” #Ukraine https://twitter.com/... @inteldoge : THIS is something I expect Russia to be behind. Not whatever happened the other day with Ukrainian government websites going down/getting defaced. That's minor league stuff. This is much more significant. https://twitter.com/... Eva / @evacide : It's Saturday night, which we all know is time to read research blog posts about malware targeting Ukrainian orgs. https://twitter.com/... Dr. Sanjana Hattotuwa / @sanjanah : The intentional malevolence, as opposed to carelessness, very worrying. Like 2017's NotPetya, what's aimed at #Ukraine risks migration to other countries & mission critical infra, that readout from Microsoft indicates may result in catastrophic data loss. @ict4peace @DStauffacher https://twitter.com/... Dan Goodin / @dangoodin001 : Sounds like NotPetya all over again https://twitter.com/... Jerry Dunleavy / @jerrydunleavy : “Microsoft Threat Intelligence Center (MSTIC) has identified evidence of a destructive malware operation targeting multiple organizations in Ukraine. This malware first appeared on victim systems in Ukraine on January 13, 2022.” https://www.microsoft.com/... Condition.Black / @shadow0pz : OK folks. Circle up. Ukrainian Government, IT Services and NGO's are being actively targeted by a MBR/File corrupter posing as a Ransomware package. Ransom is a diversion tactic meant to get the user to shutdown the box thus triggering the MBR overwrite. https://www.microsoft.com/... Brad Smith / @bradsmi : Today we shared we've detected malware placed in Ukraine government agencies. Amid tensions in the region, we're encouraging customers in Ukraine to look out for these attacks and protect themselves. https://blogs.microsoft.com/ ... Jesper / @jandersen : The big four tech companies run absolutely good security teams but it continues to be alarming that international acts of aggression have to be fielded by the private sector. https://twitter.com/... Lukasz Olejnik / @lukolejnik : According to Ukraine services, the hack and the information operation may be run by Belarusian services. We know that Belarus UNC1151 runs similar operations in the region (Germany, Poland, Lithuania). https://www.reuters.com/... https://twitter.com/...

Microsoft Security Blog

Context & Ripple Effects

The operation follows earlier BlackEnergy attacks delivered through Word documents against Ukrainian critical infrastructure, showing that Ukraine had already been a sustained target for disruptive malware. Microsoft now tracks the new activity as DEV-0586 and is assisting the Ukrainian government, while CISA has directed defenders to the company’s technical guidance.

First-order effects

  • Ukrainian organizations hit by DEV-0586 face data destruction disguised as ransomware, leaving payment or ordinary ransom-recovery procedures irrelevant.
  • Microsoft’s incident-response role and CISA’s recommendation put Microsoft’s detection and mitigation guidance at the center of the immediate defensive response.

Second-order effects

  • Ukrainian network defenders must prioritize containment, restoration, and verification of backups over ransomware-negotiation workflows because the displayed ransom demand lacks a recovery mechanism.
  • CISA’s referral to Microsoft’s analysis extends the operational lesson beyond the directly affected organizations: defenders must treat ransomware-like behavior as potentially destructive rather than financially motivated.

Third-order effects

  • If this pattern persists, destructive operations masquerading as cybercrime will make motive-based incident triage less reliable, increasing the value of rapid vendor intelligence and recovery readiness.
  • The recurrence from earlier attacks on Ukrainian critical infrastructure points to a longer-running cyber-conflict pattern in which civilian and government networks must prepare for disruption, not only espionage or extortion.

The trend: Cyber-conflict activity is increasingly using familiar criminal-malware signals as cover for operations intended to disable systems rather than monetize access.

Discussion

  • @msftsecintel @msftsecintel on x
    Microsoft identified a unique destructive malware operated by an actor tracked as DEV-0586 targeting Ukrainian organizations. Observed activity, TTPs, and IOCs shared in this new MSTIC blog. We'll update the blog as our investigation unfolds. https://www.microsoft.com/...
  • @a_greenberg Andy Greenberg on x
    A new round of data-destroying fake ransomware attacks in Ukraine appears to be small-scale for now. But it's uncomfortably similar to Russia's escalating attacks from 2015-2017 that culminated in NotPetya's $10 billion devastation. https://www.wired.com/...
  • @itsreallynick Nick Carr on x
    When our awesome #MSTIC Russia team discovered this event unfolding in real-time 🤯, here was our crime triage on how DEV-0586's destructive malware differs from 𝘵𝘺𝘱𝘪 𝘤𝘢𝘭 human-operated ransomware. “Ransom” note in the blog: https://www.microsoft.com/... - anything we missed? http…
  • @pa @pa on x
    Ukraine says Russia was behind a cyberattack that defaced government websites and it alleged that Russia is engaged in a “hybrid war” against the country https://www.independent.co.uk/ ...
  • @jaredcohen Jared Cohen on x
    In 2022, all wars will begin as cyberwars. Whether a physical front of a war opens is just a question of scale. #ukraine is the first major case study in the new year: https://www.nytimes.com/...
  • @shannonbraync Shannon Bray on x
    Microsoft is sharing this information to help others in the cybersecurity community look out for and defend against these attacks. https://blogs.microsoft.com/ ...
  • @crispinburke Crispin Burke on x
    Ukrainian authorities suspect a Belarus-based hacking group known as UNC1151, or “Ghostwriter”, defaced several Ukrainian government websites. Ukrainian intelligence also believes the campaign was a cover for more sophisticated cyber activity. https://www.reuters.com/...
  • @uscert_gov @uscert_gov on x
    ⚠️ @CISAgov recommends network defenders review the Microsoft blog on destructive malware targeting Ukrainian organizations. https://www.cisa.gov/... #Cybersecurity #InfoSec
  • @likethecoins Katie Nickels on x
    A simple threat modeling exercise. You/your leadership may be focused on the destructive attacks in Ukraine: https://www.microsoft.com/.... But if you're not in Ukraine, I'd argue threats against VMware Horizon should likely be a higher priority: https://www.huntress.com/....
  • @ciaranmartinoxf Ciaran Martin on x
    “It was unclear if the defacement was related to the far more destructive code that Microsoft said it had detected.” from ⁦@nytimes⁩ Anyone seen anything definitive on whether the defacements are or aren't connected to the more destructive stuff? https://www.nytimes.com/...
  • @williamturton William Turton on x
    Feels like we've witnessed a very familiar cycle again here something cyber happens > media reacts > people on twitter scold others for overreacting > a few days later it turns out to be a bigger deal than we knew https://twitter.com/...
  • @fsecure @fsecure on x
    .@c_gcw's thoughts on the destructive malware targeting organizations in Ukraine. Malware info >> https://www.microsoft.com/... https://twitter.com/...
  • @ffforward @ffforward on x
    File with similar basic behavior uploaded from UA as “Crypted.exe” on the 14th: https://www.virustotal.com/... Needs to be run from %temp% as Stage1.exe, however I'm only getting a loop of Stage1 > Stage2 > Stage1 etc and no traffic, so no confirmation it's the real thing. https:…
  • @r00tbsd @r00tbsd on x
    There is similar samples on VT... Are they related to the incident? If yes, why did you make the choice to put hashes from samples not on VT in the blog post? #SharingIsCaring https://twitter.com/...
  • @christopherjm Christopher Miller on x
    .@Microsoft findings back up my reporting of an uptick in malware targeting systems of Ukrainian government agencies and organizations: https://blogs.microsoft.com/ ... See my reporting here: https://twitter.com/...
  • @bushidotoken @bushidotoken on x
    “Upon execution, stage2.exe downloads the next-stage malware hosted on a Discord channel, with the download link hardcoded in the downloader” Once again, @discord CDN is supporting malware distribution, this time a destructive MBR wiper attack against Ukrainian government orgs ht…
  • @carlbildt Carl Bildt on x
    This is serious! It looks as if what was immediately seen of the cyberattack against 🇺🇦 was just there to insert malware that under instruction at some time would more or less destroy all the systems. https://twitter.com/...
  • @andersostlund @andersostlund on x
    Serious question: When does a cyber attack become an act of war? The answer will have a great impact on how the alliance approach Russia now, if indeed it was Russia who launched the attack. https://twitter.com/...
  • @remkorteweg Rem Korteweg on x
    Looks like Friday's cyberattack on UKR sites may have been cover to insert “destructive malware” which - if activated - could weaken, or knock out, Ukrainian command & control. https://twitter.com/...
  • @ilvestoomas @ilvestoomas on x
    Now *this*, as opposed to homepage defacing, is a cyber attack. https://www.microsoft.com/...
  • @totalforsvar @totalforsvar on x
    Kyiv believes a hacker group linked to Belarusian intelligence carried out a cyberattack that hit Ukrainian government websites this week and used malware similar to that used by a group tied to Russian intelligence. https://www.reuters.com/...
  • @sangernyt David Sanger on x
    There's a playbook to all this - one the private sector can sometimes see faster than the govt. can, or the intended victims. https://www.nytimes.com/...
  • @27khv Bryan MacDonald on x
    Interesting, to say the least: Friday's cyberattack targeting Ukrainian government agencies was carried out by a group linked to Belarusian intelligence services - and not by Russians, as originally claimed - according to a senior Kiev security official. https://www.rt.com/...
  • @mikko @mikko on x
    Reflections of the 2017 Notpetya attack against Ukraine. “The malware, which is designed to look like ransomware but lacking a ransom recovery mechanism, is intended to be destructive and designed to render targeted devices inoperable rather than to obtain a ransom...” https://tw…
  • @mike_eckel Mike Eckel on x
    here's what Microsoft says it's found about the malware hack/attack on Ukrainian government websites ( short version: it's bigger than realized; it's not the last of its kind, it's not a criminal group, but rather a state-sponsored agency): https://www.microsoft.com/... https://t…
  • @c_c_krebs Chris Krebs on x
    The other shoe drops on the comment made by Ukrainian official about behind the scenes destructive attacks. Good work here by @MSTIC. Who could it be? https://twitter.com/... https://twitter.com/...
  • @netspooky @netspooky on x
    Lol remember when I referred to Discord as a “popular malware hosting platform” and people were like “wait what are you talking about?” after years of already being like “hrmmm maybe something should be done about this”? The CyberWar remembers. https://www.microsoft.com/... https…
  • @snlyngaas Sean Lyngaas on x
    Microsoft “assesses that the malware, which is designed to look like ransomware but lacking a ransom recovery mechanism, is intended to be destructive and designed to render targeted devices inoperable rather than to obtain a ransom.” #Ukraine https://twitter.com/...
  • @inteldoge @inteldoge on x
    THIS is something I expect Russia to be behind. Not whatever happened the other day with Ukrainian government websites going down/getting defaced. That's minor league stuff. This is much more significant. https://twitter.com/...
  • @evacide Eva on x
    It's Saturday night, which we all know is time to read research blog posts about malware targeting Ukrainian orgs. https://twitter.com/...
  • @sanjanah Dr. Sanjana Hattotuwa on x
    The intentional malevolence, as opposed to carelessness, very worrying. Like 2017's NotPetya, what's aimed at #Ukraine risks migration to other countries & mission critical infra, that readout from Microsoft indicates may result in catastrophic data loss. @ict4peace @DStauffacher…
  • @dangoodin001 Dan Goodin on x
    Sounds like NotPetya all over again https://twitter.com/...
  • @jerrydunleavy Jerry Dunleavy on x
    “Microsoft Threat Intelligence Center (MSTIC) has identified evidence of a destructive malware operation targeting multiple organizations in Ukraine. This malware first appeared on victim systems in Ukraine on January 13, 2022.” https://www.microsoft.com/...
  • @shadow0pz Condition.Black on x
    OK folks. Circle up. Ukrainian Government, IT Services and NGO's are being actively targeted by a MBR/File corrupter posing as a Ransomware package. Ransom is a diversion tactic meant to get the user to shutdown the box thus triggering the MBR overwrite. https://www.microsoft.com…
  • @bradsmi Brad Smith on x
    Today we shared we've detected malware placed in Ukraine government agencies. Amid tensions in the region, we're encouraging customers in Ukraine to look out for these attacks and protect themselves. https://blogs.microsoft.com/ ...
  • @jandersen Jesper on x
    The big four tech companies run absolutely good security teams but it continues to be alarming that international acts of aggression have to be fielded by the private sector. https://twitter.com/...
  • @lukolejnik Lukasz Olejnik on x
    According to Ukraine services, the hack and the information operation may be run by Belarusian services. We know that Belarus UNC1151 runs similar operations in the region (Germany, Poland, Lithuania). https://www.reuters.com/... https://twitter.com/...
  • @henryjfoy Henry Foy on x
    New - US Nato ambassador @USAmbNATO @Julie_C_Smith says still looking into Ukraine cyber attack but confirms cyber is “certainly” a criteria to trigger threatened western sanctions against Russia for any further aggressive action against its neighbour https://www.ft.com/...
  • @jenniferjjacobs Jennifer Jacobs on x
    Biden officials have no attribution at this time, NSC says, for Ukraine's worst cyber attack in 4 years, which brought down websites of govt agencies for hours. @POTUS has been briefed on attack. Admin assessing impact which NSC says “seems limited.” https://www.bloomberg.com/...
  • @timroemeraz Tim Roemer on x
    I can't emphasis the severity of this cyber attack enough. Russia took over 70 Ukrainian government websites. What else can they and will they take over with a #cyberattack in the world? PS: “Be afraid” is definitely going on our Cyber Command wall for motivation. #cybersecurity …
  • @antonioarellano Antonio Arellano on x
    A number of Ukrainian government websites are currently down due to “a massive cyberattack” with threatening text warning Ukrainians to “be afraid and wait for the worst” and alleging their personal information has been hacked https://www.cnn.com/...
  • @sentletse @sentletse on x
    It helps if proof could be availed https://twitter.com/...
  • @paulniland Paul Niland on x
    Realistically, where else? Who else is at war with Ukraine? https://twitter.com/...
  • @maxseddon Max Seddon on x
    Ukraine says ‘all evidence points to Russia’ in the massive cyber attack that left malware on dozens of government systems - with a possible assist from Belarus https://www.ft.com/...