Microsoft identifies a destructive malware operation targeting Ukrainian organizations; the malware looks like ransomware but lacks a ransom recovery mechanism
European Union simulated a cyber attack on a fictitious Finnish power company Vilius Petkauskas / cybernews.com : Belarus state hackers suspected behind Ukraine cyberattack Grugq / grugq's domain : Ukraine my heart, cyber just for show? Jonathan Greig / ZDNet : Microsoft says ‘destructive malware’ being used against Ukrainian organizations Benzinga : Microsoft Warns Ukrainian Government Computer Systems Infected; Security Official Suspects Russian Intelligence Graham Cluley : Data-wiping malware hitting Ukrainian computers displays fake ransom demand Michael Novinson / CRN : Microsoft: Ukrainian Government Hit With Destructive Malware Nathaniel Mott / PCMag : Microsoft: Ukrainian Companies Are Being Targeted by Destructive Malware Mike Lennon / SecurityWeek : Microsoft Uncovers Destructive Malware Used in Ukraine Cyberattacks The Moscow Times : Ukraine Says Has ‘Evidence’ Russia Behind Cyberattack Surur / MSPoweruser : Microsoft assisting Ukrainian government in fighting off Russian cyber-attack CISA : Microsoft Warns of Destructive Malware Targeting Ukrainian Organizations Mychael Schnell / The Hill : Ukraine government agencies' computer systems infected with malware, Microsoft says ANI / Livemint : Microsoft warns of destructive malware in computer systems of Ukrainian state institutions Catalin Cimpanu / The Record : Microsoft: Data-wiping malware disguised as ransomware targets Ukraine again Ravie Lakshmanan / The Hacker News : A New Destructive Malware Targeting Ukrainian Government and Business Entities Anirudh Saligrama / Reuters : Microsoft says it observed destructive malware in systems belonging to several Ukraine govt agencies Eduard Gismatullin / Bloomberg : Microsoft Finds Destructive Malware in Attacks Targeting Ukraine Tweets: @msftsecintel : Microsoft identified a unique destructive malware operated by an actor tracked as DEV-0586 targeting Ukrainian organizations. Observed activity, TTPs, and IOCs shared in this new MSTIC blog. We'll update the blog as our investigation unfolds. https://www.microsoft.com/... @uscert_gov : ⚠️ @CISAgov recommends network defenders review the Microsoft blog on destructive malware targeting Ukrainian organizations. https://www.cisa.gov/... #Cybersecurity #InfoSec Andy Greenberg / @a_greenberg : A new round of data-destroying fake ransomware attacks in Ukraine appears to be small-scale for now. But it's uncomfortably similar to Russia's escalating attacks from 2015-2017 that culminated in NotPetya's $10 billion devastation. https://www.wired.com/... Nick Carr / @itsreallynick : When our awesome #MSTIC Russia team discovered this event unfolding in real-time 🤯, here was our crime triage on how DEV-0586's destructive malware differs from 𝘵𝘺𝘱𝘪 𝘤𝘢𝘭 human-operated ransomware. “Ransom” note in the blog: https://www.microsoft.com/... - anything we missed? https://twitter.com/... https://twitter.com/... @pa : Ukraine says Russia was behind a cyberattack that defaced government websites and it alleged that Russia is engaged in a “hybrid war” against the country https://www.independent.co.uk/ ... Jared Cohen / @jaredcohen : In 2022, all wars will begin as cyberwars. Whether a physical front of a war opens is just a question of scale. #ukraine is the first major case study in the new year: https://www.nytimes.com/... Shannon Bray / @shannonbraync : Microsoft is sharing this information to help others in the cybersecurity community look out for and defend against these attacks. https://blogs.microsoft.com/ ... Crispin Burke / @crispinburke : Ukrainian authorities suspect a Belarus-based hacking group known as UNC1151, or “Ghostwriter”, defaced several Ukrainian government websites. Ukrainian intelligence also believes the campaign was a cover for more sophisticated cyber activity. https://www.reuters.com/... Katie Nickels / @likethecoins : A simple threat modeling exercise. You/your leadership may be focused on the destructive attacks in Ukraine: https://www.microsoft.com/.... But if you're not in Ukraine, I'd argue threats against VMware Horizon should likely be a higher priority: https://www.huntress.com/.... Ciaran Martin / @ciaranmartinoxf : “It was unclear if the defacement was related to the far more destructive code that Microsoft said it had detected.” from @nytimes Anyone seen anything definitive on whether the defacements are or aren't connected to the more destructive stuff? https://www.nytimes.com/... William Turton / @williamturton : Feels like we've witnessed a very familiar cycle again here something cyber happens > media reacts > people on twitter scold others for overreacting > a few days later it turns out to be a bigger deal than we knew https://twitter.com/... @fsecure : .@c_gcw's thoughts on the destructive malware targeting organizations in Ukraine. Malware info >> https://www.microsoft.com/... https://twitter.com/... @ffforward : File with similar basic behavior uploaded from UA as “Crypted.exe” on the 14th: https://www.virustotal.com/... Needs to be run from %temp% as Stage1.exe, however I'm only getting a loop of Stage1 > Stage2 > Stage1 etc and no traffic, so no confirmation it's the real thing. https://twitter.com/... @r00tbsd : There is similar samples on VT... Are they related to the incident? If yes, why did you make the choice to put hashes from samples not on VT in the blog post? #SharingIsCaring https://twitter.com/... Christopher Miller / @christopherjm : .@Microsoft findings back up my reporting of an uptick in malware targeting systems of Ukrainian government agencies and organizations: https://blogs.microsoft.com/ ... See my reporting here: https://twitter.com/... @bushidotoken : “Upon execution, stage2.exe downloads the next-stage malware hosted on a Discord channel, with the download link hardcoded in the downloader” Once again, @discord CDN is supporting malware distribution, this time a destructive MBR wiper attack against Ukrainian government orgs https://twitter.com/... Carl Bildt / @carlbildt : This is serious! It looks as if what was immediately seen of the cyberattack against 🇺🇦 was just there to insert malware that under instruction at some time would more or less destroy all the systems. https://twitter.com/... @andersostlund : Serious question: When does a cyber attack become an act of war? The answer will have a great impact on how the alliance approach Russia now, if indeed it was Russia who launched the attack. https://twitter.com/... Rem Korteweg / @remkorteweg : Looks like Friday's cyberattack on UKR sites may have been cover to insert “destructive malware” which - if activated - could weaken, or knock out, Ukrainian command & control. https://twitter.com/... @ilvestoomas : Now *this*, as opposed to homepage defacing, is a cyber attack. https://www.microsoft.com/... @totalforsvar : Kyiv believes a hacker group linked to Belarusian intelligence carried out a cyberattack that hit Ukrainian government websites this week and used malware similar to that used by a group tied to Russian intelligence. https://www.reuters.com/... David Sanger / @sangernyt : There's a playbook to all this - one the private sector can sometimes see faster than the govt. can, or the intended victims. https://www.nytimes.com/... Bryan MacDonald / @27khv : Interesting, to say the least: Friday's cyberattack targeting Ukrainian government agencies was carried out by a group linked to Belarusian intelligence services - and not by Russians, as originally claimed - according to a senior Kiev security official. https://www.rt.com/... @mikko : Reflections of the 2017 Notpetya attack against Ukraine. “The malware, which is designed to look like ransomware but lacking a ransom recovery mechanism, is intended to be destructive and designed to render targeted devices inoperable rather than to obtain a ransom...” https://twitter.com/... Mike Eckel / @mike_eckel : here's what Microsoft says it's found about the malware hack/attack on Ukrainian government websites ( short version: it's bigger than realized; it's not the last of its kind, it's not a criminal group, but rather a state-sponsored agency): https://www.microsoft.com/... https://twitter.com/... Chris Krebs / @c_c_krebs : The other shoe drops on the comment made by Ukrainian official about behind the scenes destructive attacks. Good work here by @MSTIC. Who could it be? https://twitter.com/... https://twitter.com/... @netspooky : Lol remember when I referred to Discord as a “popular malware hosting platform” and people were like “wait what are you talking about?” after years of already being like “hrmmm maybe something should be done about this”? The CyberWar remembers. https://www.microsoft.com/... https://twitter.com/... https://twitter.com/... Sean Lyngaas / @snlyngaas : Microsoft “assesses that the malware, which is designed to look like ransomware but lacking a ransom recovery mechanism, is intended to be destructive and designed to render targeted devices inoperable rather than to obtain a ransom.” #Ukraine https://twitter.com/... @inteldoge : THIS is something I expect Russia to be behind. Not whatever happened the other day with Ukrainian government websites going down/getting defaced. That's minor league stuff. This is much more significant. https://twitter.com/... Eva / @evacide : It's Saturday night, which we all know is time to read research blog posts about malware targeting Ukrainian orgs. https://twitter.com/... Dr. Sanjana Hattotuwa / @sanjanah : The intentional malevolence, as opposed to carelessness, very worrying. Like 2017's NotPetya, what's aimed at #Ukraine risks migration to other countries & mission critical infra, that readout from Microsoft indicates may result in catastrophic data loss. @ict4peace @DStauffacher https://twitter.com/... Dan Goodin / @dangoodin001 : Sounds like NotPetya all over again https://twitter.com/... Jerry Dunleavy / @jerrydunleavy : “Microsoft Threat Intelligence Center (MSTIC) has identified evidence of a destructive malware operation targeting multiple organizations in Ukraine. This malware first appeared on victim systems in Ukraine on January 13, 2022.” https://www.microsoft.com/... Condition.Black / @shadow0pz : OK folks. Circle up. Ukrainian Government, IT Services and NGO's are being actively targeted by a MBR/File corrupter posing as a Ransomware package. Ransom is a diversion tactic meant to get the user to shutdown the box thus triggering the MBR overwrite. https://www.microsoft.com/... Brad Smith / @bradsmi : Today we shared we've detected malware placed in Ukraine government agencies. Amid tensions in the region, we're encouraging customers in Ukraine to look out for these attacks and protect themselves. https://blogs.microsoft.com/ ... Jesper / @jandersen : The big four tech companies run absolutely good security teams but it continues to be alarming that international acts of aggression have to be fielded by the private sector. https://twitter.com/... Lukasz Olejnik / @lukolejnik : According to Ukraine services, the hack and the information operation may be run by Belarusian services. We know that Belarus UNC1151 runs similar operations in the region (Germany, Poland, Lithuania). https://www.reuters.com/... https://twitter.com/...
Context & Ripple Effects
The operation follows earlier BlackEnergy attacks delivered through Word documents against Ukrainian critical infrastructure, showing that Ukraine had already been a sustained target for disruptive malware. Microsoft now tracks the new activity as DEV-0586 and is assisting the Ukrainian government, while CISA has directed defenders to the company’s technical guidance.
First-order effects
- Ukrainian organizations hit by DEV-0586 face data destruction disguised as ransomware, leaving payment or ordinary ransom-recovery procedures irrelevant.
- Microsoft’s incident-response role and CISA’s recommendation put Microsoft’s detection and mitigation guidance at the center of the immediate defensive response.
Second-order effects
- Ukrainian network defenders must prioritize containment, restoration, and verification of backups over ransomware-negotiation workflows because the displayed ransom demand lacks a recovery mechanism.
- CISA’s referral to Microsoft’s analysis extends the operational lesson beyond the directly affected organizations: defenders must treat ransomware-like behavior as potentially destructive rather than financially motivated.
Third-order effects
- If this pattern persists, destructive operations masquerading as cybercrime will make motive-based incident triage less reliable, increasing the value of rapid vendor intelligence and recovery readiness.
- The recurrence from earlier attacks on Ukrainian critical infrastructure points to a longer-running cyber-conflict pattern in which civilian and government networks must prepare for disruption, not only espionage or extortion.
The trend: Cyber-conflict activity is increasingly using familiar criminal-malware signals as cover for operations intended to disable systems rather than monetize access.