DEFCON 3 · ELEVATED OBSERVATORY STATUS
04:24:00 UTC
EXPLORE DIRECTORY
LAST SYNCHRONIZED: 2026-08-25
malware

HermeticWiper (FoxBlade / Trojan.KillDisk)

EXECUTIVE INTELLIGENCE SUMMARY

Destructive data-wiping malware weaponized by Sandworm / Russian state operators, weaponizing signed partition drivers to destroy Master Boot Records (MBR) and VSS shadow copies.

HermeticWiper leverages legitimate, signed EaseUS Partition Master drivers (empntdrv.sys) to gain raw block-level disk access across physical drives (\\.\PhysicalDrive0-9), systematically fragmenting NTFS partition tables, MFT, and master boot records beyond forensic recovery.

SOURCE CITATIONS & ATTESTATIONS (1)
Mandiant Threat Intelligence Report: HermeticWiper ForensicsMandiant

Anatomy of Destructive Wiper Deployments

TELEMETRY CARDID: malware-hermetic-wiper
ENTITY TYPE
malware
INDEXED TAGS
#wiper#destructive#raw_disk_access#driver_abuse#sandworm#hybrid_warfare