Description
WhisperGate is destructive malware that targets Ukrainian organizations, first observed in January 2022 in the lead up to the full scale invasion. Its multi stage chain included file corruption, a fake ransomware demand, and disk wiping, an approach designed to maximize damage while obscuring intent. Researchers view it as part of the broader pattern of destructive intrusions that accompanied the conflict, and its detections warrant immediate escalation and recovery planning.
Stats
- First seen
- March 2022
- Last seen
- October 2026
Also known as
Whispergate
MITRE ATT&CK techniques
28 techniques across 6 tactics.
TA0002 Execution
TA0005 Stealth
- T1027Obfuscated Files or Information
- T1027.013Encrypted/Encoded File
- T1036Masquerading
- T1055Process Injection
- T1055.012Process Hollowing
- T1070Indicator Removal
- T1070.004File Deletion
- T1134Access Token Manipulation
- T1134.002Create Process with Token
- T1140Deobfuscate/Decode Files or Information
- T1218System Binary Proxy Execution
- T1218.004InstallUtil
- T1497Virtualization/Sandbox Evasion
- T1542Pre-OS Boot
- T1542.003Bootkit
- T1620Reflective Code Loading
TA0007 Discovery
TA0011 Command and Control
TA0040 Impact
TA0112 Defense Impairment
- T1685Disable or Modify Tools
Associated groups
Alert name variants
| Alert Name |
|---|
| ByteCode-MSIL.Trojan.Whispergate |
| ByteCode-MSIL.Trojan.WhisperGate |
| Gen:Variant.WhisperGate.3 |
| Script-BAT.Trojan.WhisperGate |
| Trojan.WhisperGate.1 |
| Win32.Trojan.Whispergate |
| Win32.Trojan.WhisperGate |



