Thursday June 26, 2025
Advertisement
Edit
The Current Bite The Current Bite
  • most recent news
  • trending news
  • most read
  • All Video
  • Image gallery
  • more
Technology

Introducing Windows 11

August 21, 2021
Technology

Launching Mi 5X Series

August 26, 2021
Mobile

Infinix Hot 11S India

August 27, 2021
News

Xiaomi to invest $10bn

September 1, 2021
News

FBI Alerts About Hive

September 1, 2021
Mobile

OnePlus Buds Pro Matte

September 2, 2021
  • Accessibility
  • Help
  • Contact
  • About qoxag
The Current Bite The Current Bite

Breaking News

EXCLUSIVE: Rani Mukerji reunites with Shah Rukh Khan on King;

ThalapathyVijay’s #GOAT is a cinematic masterpiece!

Border 2 Gets Even Stronger! Diljit Dosanjh Joins the Squad

Fans Demand Mr. India 2 After Viral BTS Pic

Rajkummar Rao Shares Unseen BTS Pic from Stree 2: “Deleted

AMMA Leadership Resigns Amid Sexual Misconduct Allegations

“Stree 2 Success Party: New Photos of Shraddha Kapoor, Kriti

“Explained: The Arshad Warsi-Prabhas Controversy—’Joker’ Comment and Reactions from Nani

“‘Stree 2’ Global Box Office Update on Day 7: Shraddha

IC 814: The Kandahar Hijack | Official Trailer | Vijay

The Current Bite The Current Bite
  • Home
  • News
  • Technology
  • Entertainment
  • Sports
  • Gadgets
  • Finance
  • TCB-How to
  1. Home
  2. News
  3. Microsoft Warns of Destructive Cyberattack on Ukrainian
 Microsoft Warns of Destructive Cyberattack on Ukrainian
News Technology

Microsoft Warns of Destructive Cyberattack on Ukrainian

by VICKY January 20, 2022 0 Comment

Microsoft identified a unique destructive malware operated by an actor tracked as DEV-0586 targeting Ukrainian organizations. Observed activity, TTPs, and IOCs shared in this new MSTIC blog. We'll update the blog as our investigation unfolds. https://t.co/wBB82gp6TX

— Microsoft Security Intelligence (@MsftSecIntel) January 16, 2022

Microsoft Threat Intelligence Center (MSTIC) has identified evidence of a destructive malware operation targeting multiple organizations in Ukraine. This malware first appeared on victim systems in Ukraine on January 13, 2022. Microsoft is aware of the ongoing geopolitical events in Ukraine and surrounding region and encourages organizations to use the information in this post to proactively protect from any malicious activity.

At present and based on Microsoft visibility, our investigation teams have identified the malware on dozens of impacted systems and that number could grow as our investigation continues. These systems span multiple government, non-profit, and information technology organizations, all based in Ukraine. We do not know the current stage of this attacker’s operational cycle or how many other victim organizations may exist in Ukraine or other geographic locations. However, it is unlikely these impacted systems represent the full scope of impact as other organizations are reporting.

“This is not the first time or even the second time that Ukrainian Internet resources have been attacked since the beginning of the Russian military aggression,” the Ukrainian Information Ministry said in a statement.

Stage 1: Overwrite Master Boot Record to display a faked ransom note

The malware resides in various working directories, including C:\PerfLogs, C:\ProgramData, C:\, and C:\temp, and is often named stage1.exe. In the observed intrusions, the malware executes via Impacket, a publicly available capability often used by threat actors for lateral movement and execution.

Stage 2: File corrupter malware

Stage2.exe is a downloader for a malicious file corrupter malware. Upon execution, stage2.exe downloads the next-stage malware hosted on a Discord channel, with the download link hardcoded in the downloader. The next-stage malware can best be described as a malicious file corrupter. Once executed in memory, the corrupter locates files in certain directories on the system with one of the following hardcoded file extensions:

Recommended customer actions

MSTIC and the Microsoft security teams are working to create and implement detections for this activity. To date, Microsoft has implemented protections to detect this malware family as WhisperGate (e.g., DoS:Win32/WhisperGate.A!dha) via Microsoft Defender Antivirus and Microsoft Defender for Endpoint, wherever these are deployed on-premises and cloud environments. We are continuing the investigation and will share significant updates with affected customers, as well as public and private sector partners, as get more information. The techniques used by the actor and described in the this post can be mitigated by adopting the security considerations provided below:

 

Detections

Microsoft 365 Defender

 

Share This:

  • 1
    Facebook
Tags: #cyberattackonukraine #microsoftwarnsukraine #tcb #technology
Previous post
Next post

VICKY

administrator

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Categories

  • Entertainment
  • Finance
  • Gaming
  • Mobile
  • Movies Trailers
  • News
  • Sports
  • TCB-How to
  • Technology
  • Uncategorized
Most Recent
Entertainment

EXCLUSIVE: Rani Mukerji reunites with Shah Rukh

May 16, 2025
Entertainment

ThalapathyVijay’s #GOAT is a cinematic masterpiece!

September 6, 2024
Entertainment

Border 2 Gets Even Stronger! Diljit Dosanjh

September 6, 2024
Entertainment

Fans Demand Mr. India 2 After Viral

August 28, 2024
Social Profile

Daily Newsletter

Get all the top stories from Qoxag to keep track.

RELATED Stories for you
Entertainment

Citadel: Honey Bunny Teaser | Raj &

by VICKY August 1, 2024

The upcoming series, Citadel: Honey Bunny, directed by the dynamic duo Raj & DK,

News Technology

Dangerous new malware dances past more than

by VICKY July 9, 2022

Specialists have found a new malware test fit for stowing away from more than

Mobile Technology

Tips for how transfer whatsapp chat from

by VICKY June 21, 2022

The year before, WhatsApp announced a new feature that lets users transfer their chat

Copyright © 2025 Teqtive Solutions. All Right Reserved.