Description
CaddyWiper is destructive malware that wipes disk data on infected Windows systems, destroying files and partition structures rather than encrypting them for ransom. Researchers discovered it in the wave of destructive attacks against Ukrainian organizations in early 2022, and it could erase domain controller data to cripple an entire network. Because wiping is irreversible without backups, defenders treat CaddyWiper detections as evidence of a severe, targeted intrusion.
Stats
- First seen
- May 2022
- Last seen
- October 2026
Also known as
Caddywiper
MITRE ATT&CK techniques
7 techniques across 4 tactics.
TA0002 Execution
- T1106Native API
TA0007 Discovery
Associated campaigns
Alert name variants
| Alert Name |
|---|
| Gen:Variant.Bulz.CaddyWiper.159724 |
| Win32.Network.CaddyWiper |
| Win32.Ransomware.CaddyWiper |
| Win32.Trojan.Caddywiper |
| Win32.Trojan.CaddyWiper |
Related IPS Signatures
| Signature Name |
|---|
| MALWARE-OTHER Win.Trojan.CaddyWiper download attempt |