One Article Review

Accueil - L'article:
Source Fortinet.webp Fortinet ThreatSignal
Identifiant 4342545
Date de publication 2022-03-25 14:41:37 (vue: 2022-03-25 22:05:26)
Titre Another Wiper Malware Targeted Enterprises in Ukraine #DoubleZero
Texte FortiGuard Labs is aware that enterprises in Ukraine were targeted by another wiper malware. Dubbed "DoubleZero," the malware was distributed in a zip archive and destroys the compromised machine by overwriting files and deleting registry keys.Why is this Significant?This is significant because DoubleZero is the latest wiper malware used in the current Russia-Ukraine war and aims to destroy machines belonging to enterprises in Ukraine.FortiGuard Labs previous published multiple Threat Signals on other wiper malware that targeted Ukraine. See the Appendix for links to "Additional Wiper Malware Deployed in Ukraine #CaddyWiper," "New Wiper Malware Discovered Targeting Ukrainian Interests" and "Wiper Malware Hit Ukrainian Organizations."How Widespread is the Malware?At this time, there is no report that DoubleZero affected organizations outside of Ukraine.How does DoubleZero Work?DoubleZero was distributed in several ZIP archives, one of which is called "Virus ... extremely dangerous !!!. Zip." Once DoubleZero runs, it overwrites or uses API calls to zero out non-system files system files before moving on to overwrite critical system files and registry keys.What is the Status of Coverage?FortiGuard Labs provides the following AV coverage against the files involved in the attack:MSIL/DZeroWiper.CK!tr
Envoyé Oui
Condensat #caddywiper #doublezero additional affected against aims another api appendix archive archives attack:msil/dzerowiper aware because before belonging called calls compromised coverage critical current dangerous deleting deployed destroy destroys discovered distributed does doublezero dubbed enterprises extremely files following fortiguard hit how interests involved keys labs latest links machine machines malware moving multiple new non once one organizations other out outside overwrite overwrites overwriting previous provides published registry report runs russia see several signals significant status system targeted targeting threat time ukraine ukrainian used uses virus war what which why widespread wiper work zero zip
Tags Malware Threat
Stories
Notes
Move


L'article ne semble pas avoir été repris aprés sa publication.


L'article ne semble pas avoir été repris sur un précédent.
My email: