CaddyWiper — Malware Profile
CaddyWiper is a destructive data wiper that has been used in attacks against organizations in Ukraine since at least March 2022.
MITRE ATT&CK techniques (7)
- T1057 Process Discovery
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1106 Native API
- T1222.001 Windows Permissions
- T1485 Data Destruction
- T1561.002 Disk Structure Wipe
Attributed threat actors
- Sandworm Team machine-inferred link
- APT28 machine-inferred link