hermeticwiper (2)

Activity Summary - Week Ending on 25 March 2022:

  • Red Sky Alliance identified 15,245 connections from new IP’s checking in with our Sinkholes
  • Malicious Keylogger data is back with 24 Keylogged emails
  • Analysts identified 1,081 new IP addresses participating in various Botnets
  • CaddyWiper
  • CryptBot
  • Russian Cyber Attacks – Train your Machine
  • IssacWiper
  • A 3rd Wipper (after HermeticWiper and IzaakWiper)
  • Wiper remediation

Link to full report: IR-22-084-001_weekly084.pdf

10167240466?profile=RESIZE_400xAs news continues to break about the ongoing crisis in Western Europe, Cyber Security professionals have been busy making sense of the role that presumably planned cyber-attacks have played in the conflict between Russia and Ukraine.  A number of Russian cyber-attacks have served as a prelude to a physical invasion of Ukraine.  There is a lot of information from the past two months to unpack and new events are continuing to be reported.

A quick review of the cyber events leading up to boots on t