ZeroHour
Schneier on Securitypublished ()ingested Bruce Schneier

CryWiper Data Wiper Targeting Russian Sites

highMalwareimportance 42
Full article133 words · extracted from schneier.com · click to collapse

Kaspersky is reporting on a data wiper masquerading as ransomware that is targeting local Russian government networks.

The Trojan corrupts any data that’s not vital for the functioning of the operating system. It doesn’t affect files with extensions .exe, .dll, .lnk, .sys or .msi, and ignores several system folders in the C:\Windows directory. The malware focuses on databases, archives, and user documents.

So far, our experts have seen only pinpoint attacks on targets in the Russian Federation. However, as usual, no one can guarantee that the same code won’t be used against other targets.

Nothing leading to an attribution.

News article.

Slashdot thread.

Tags: data destruction, malware, ransomware, Russia

Posted on December 6, 2022 at 7:04 AM13 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.schneier.com/blog/archives/2022/12/crywiper-data-wiper-targeting-russian-sites.html