Netskope Threat Labs

WhisperGate

ATP Sandbox Adv. HeuristicsAVNetskope IPS

WhisperGate is destructive malware that targets Ukrainian organizations, first observed in January 2022 in the lead up to the full scale invasion. Its multi stage chain included file corruption, a fake ransomware demand, and disk wiping, an approach designed to maximize damage while obscuring intent. Researchers view it as part of the broader pattern of destructive intrusions that accompanied the conflict, and its detections warrant immediate escalation and recovery planning.

First seen
March 2022
Last seen
October 2026
Whispergate

28 techniques across 6 tactics.

TA0002 Execution

TA0005 Stealth

TA0007 Discovery

  • T1083File and Directory Discovery
  • T1135Network Share Discovery
  • T1518Software Discovery
  • T1680Local Storage Discovery

TA0011 Command and Control

TA0040 Impact

TA0112 Defense Impairment

  • T1685Disable or Modify Tools
Alert Name
ByteCode-MSIL.Trojan.Whispergate
ByteCode-MSIL.Trojan.WhisperGate
Gen:Variant.WhisperGate.3
Script-BAT.Trojan.WhisperGate
Trojan.WhisperGate.1
Win32.Trojan.Whispergate
Win32.Trojan.WhisperGate