Netskope Threat Labs

CaddyWiper

ATP Sandbox Adv. HeuristicsAVNetskope IPS

CaddyWiper is destructive malware that wipes disk data on infected Windows systems, destroying files and partition structures rather than encrypting them for ransom. Researchers discovered it in the wave of destructive attacks against Ukrainian organizations in early 2022, and it could erase domain controller data to cripple an entire network. Because wiping is irreversible without backups, defenders treat CaddyWiper detections as evidence of a severe, targeted intrusion.

First seen
May 2022
Last seen
October 2026
Caddywiper

7 techniques across 4 tactics.

TA0002 Execution

TA0007 Discovery

  • T1057Process Discovery
  • T1082System Information Discovery
  • T1083File and Directory Discovery

TA0040 Impact

TA0112 Defense Impairment

  • T1222File and Directory Permissions Modification
Alert Name
Gen:Variant.Bulz.CaddyWiper.159724
Win32.Network.CaddyWiper
Win32.Ransomware.CaddyWiper
Win32.Trojan.Caddywiper
Win32.Trojan.CaddyWiper