κατασκευή ιστοσελίδων ρόδος

TECH - WEB DEVELOPMENT NEWS

Get the latest tech - web development news and analysis on industry around the world.

  • HOME
You are here: Home / INDUSTRY NEWS / New PathWiper Malware Attacking Critical Infrastructure To Deploy Administrative Tools
άμυνα
.

New PathWiper Malware Attacking Critical Infrastructure To Deploy Administrative Tools

06/06/2025

A sophisticated cyber attack campaign has emerged targeting Ukraine’s critical infrastructure, utilizing a previously unknown destructive malware variant that researchers have designated “PathWiper.”

This latest threat represents a significant escalation in the ongoing cyber warfare landscape, demonstrating advanced capabilities designed to cause maximum disruption to essential services and systems across the embattled nation.

The malware campaign exploits legitimate endpoint administration frameworks to gain initial access and deploy its destructive payload across connected systems within targeted organizations.

Unlike conventional malware that seeks to maintain persistence or steal data, PathWiper functions as a wiper – a particularly destructive class of malware designed to permanently destroy data and render systems inoperable by overwriting critical file system components with randomized data.

Cisco Talos analysts identified this destructive attack during their investigation of a compromised critical infrastructure entity within Ukraine, attributing the campaign to a Russia-nexus advanced persistent threat actor with high confidence.

The attribution assessment relies on overlapping tactics, techniques, and procedures observed in previous destructive campaigns targeting Ukrainian entities, as well as similarities in wiper capabilities previously deployed against the country’s infrastructure.

The continued emergence of sophisticated wiper variants like PathWiper underscores the persistent and evolving threat landscape facing Ukraine’s critical infrastructure, even as the conflict with Russia extends into its fourth year.

This latest discovery highlights how threat actors continue refining their destructive capabilities, adapting their methodologies to maximize impact against essential services that civilian populations depend upon.

Infection Mechanism and Deployment Strategy

PathWiper’s deployment methodology reveals a carefully orchestrated attack chain that leverages compromised administrative access to maximize distribution efficiency across target networks.

The initial compromise appears to center on gaining unauthorized access to legitimate endpoint administration consoles, which threat actors then exploit to issue malicious commands across all connected endpoints within the victim environment.

The attack progression begins when compromised administrative tools execute batch files containing VBScript commands designed to mimic legitimate administrative operations.

Specifically, the malicious command C:WINDOWSSystem32WScript.exe C:WINDOWSTEMPuacinstall.vbs initiates the deployment sequence, followed by the execution of the PathWiper executable disguised as C:WINDOWSTEMPsha256sum.exe.

This naming convention deliberately mimics common system utilities, suggesting the attackers possessed detailed knowledge of the target environment’s administrative processes and standard operational procedures.

The malware’s sophisticated approach to file system destruction involves programmatically identifying all connected storage media, including physical drives, network shares, and removable devices before launching parallel threads to maximize destruction efficiency.

PathWiper specifically targets critical NTFS file system artifacts including the Master Boot Record, Master File Table, and various system logs, ensuring comprehensive data destruction that renders affected systems completely inoperable.

Speed up and enrich threat investigations with Threat Intelligence Lookup! -> 50 trial search requests
Source: cybersecuritynews.com

Filed Under: INDUSTRY NEWS Tagged With: Source-10

QNAP NetBak Replicator Vulnerability Let Attackers Execute Unauthorized Code

QNAP has released a security advisory detailing a vulnerability in its NetBak Replicator utility that could allow local attackers to execute unauthorized code. The flaw, identified as CVE-2025-57714, has been rated as “Important” and affects specific versions of the backup and restore software. The company has already issued a patch and is urging users to update their systems to prevent … [Read More...]

How Windows Command-line Utility PsExec Can Be Abused To Execute Malicious Code

PsExec represents one of the most contradictory tools in the cybersecurity landscape, a legitimate system administration utility that has become a cornerstone of malicious lateral movement campaigns. Recent threat intelligence reports indicate that PsExec remains among the top five tools used in cyberattacks as of 2025, with ransomware groups like Medusa, LockBit, and Kasseika actively … [Read More...]

You'd think this was a real Stream Deck, but this genius DIYer 3D printed it and made it smart-home ready

Elgato's Stream Deck isn't meant for everyone, but it's one of the most widely adopted devices in recent years, especially among streamers, content creators, and productivity enthusiasts. Stream Deck's growing popularity also led to other players entering the space to compete with Corsair and giving users more choices. However, these aren't the only options, as it's pretty simple to build your own … [Read More...]

PoC Exploit Released for Remotely Exploitable Oracle E-Business Suite 0-Day Vulnerability

A critical zero-day vulnerability in Oracle E-Business Suite has emerged as a significant threat to enterprise environments, with proof-of-concept (PoC) exploit code now publicly available.  CVE-2025-61882 presents a severe security risk, achieving a maximum CVSS 3.1 score of 9.8 and enabling remote code execution without authentication across multiple Oracle E-Business Suite … [Read More...]

Zimbra Zero-Day Exploited to Target Brazilian Military via Malicious ICS Files

Oct 06, 2025Ravie LakshmananEmail Security / Zero-Day A now patched security vulnerability in Zimbra Collaboration was exploited as a zero-day earlier this year in cyber attacks targeting the Brazilian military. Tracked as CVE-2025-27915 (CVSS score: 5.4), the vulnerability is a stored cross-site scripting (XSS) vulnerability in the Classic Web Client that arises as a result of insufficient … [Read More...]

Oppo Reno 15 Series Key Specifications and India Launch Timeline Leaked

Oppo Reno 15 series, which is expected to comprise the Oppo Reno 15, Reno Pro, and Reno 15 Pro+, might debut in China in the second half of 2025. This means that its launch could be weeks away, or it might debut in a couple of months. A tipster has now revealed that the smartphone lineup has entered the testing phase in global markets, including India. The India launch timeline of the Oppo Reno 15 … [Read More...]

iQOO Neo 11 Key Specifications Leaked; Could Feature Snapdragon 8 Elite Chipset, 7,500mAh Battery

iQOO appears to be preparing for the launch of the iQOO Neo 11, which could arrive in China and eventually make its way to global markets. Although the Vivo sub-brand has yet to reveal any plans for a new Neo series smartphone, a tipster has leaked key specifications that point to a significant upgrade over the existing Neo 10 model. The purported iQOO Neo 11 is expected to feature a … [Read More...]

This cozy medieval city builder with 85% positive Steam reviews is still on discount

Well, that's another big Steam seasonal sale in the books. How did yours go? I didn't pick up a ton of titles this time around, but I still scored some nice discounts on games like The Roottrees Are Dead, so I'm still pleased. Source: xda-developers.com … [Read More...]

Moto G06 Power India Launch Date Announced; Key Features, Flipkart Availability Confirmed

Moto G06 Power was unveiled at IFA 2025 alongside the standard Moto G06 and Motorola Edge 60 Neo in September. The company has now announced that the Power variant will arrive in India soon. Alongside confirming the launch date, Motorola has revealed some key features of the upcoming handset. The Indian version is expected to share similarities with its global counterpart. It will be available in … [Read More...]

Who Will Be Apple’s Next CEO After Tim Cook? John Ternus Could Reportedly Take Charge

Apple's list of senior executives who have left the company is growing long. From former design chief Jony Ive and retail head Angela Ahrendts in 2019 to former Chief Financial Officer, Luca Maestri, and former Chief Operating Officer, Jeff Williams, in the last two years, the company has lost a significant part of its vanguard. While the Cupertino-based tech giant has been able to find … [Read More...]

Tags

Source-1 Source-2 Source-3 Source-4 Source-5 Source-6 Source-7 Source-8 Source-9 Source-10 Source-12 Source-13 Source-15 Source-16

Tech Web Development News

This is a PERSONAL and PRIVATE WEBPAGE. Please leave this page. Contact me via email : admin@news-6.com about anything you would like to ask or problem.

Tech News

Disclaimer!
In every post is written below the original source of the post. Copyrights belong on their owners.

Web Development News

HOTELS – CRUISES – CARS – TRAVEL

Recent Posts

  • QNAP NetBak Replicator Vulnerability Let Attackers Execute Unauthorized Code
  • How Windows Command-line Utility PsExec Can Be Abused To Execute Malicious Code
  • You'd think this was a real Stream Deck, but this genius DIYer 3D printed it and made it smart-home ready
  • PoC Exploit Released for Remotely Exploitable Oracle E-Business Suite 0-Day Vulnerability
  • Zimbra Zero-Day Exploited to Target Brazilian Military via Malicious ICS Files

Technology - Seo

Categories

  • INDUSTRY NEWS

World Industry News

Privacy & Cookies: This site uses cookies.
To find out more, as well as how to remove or block these, see here: Our Cookie Policy
TECH - WEB DEVELOPMENT NEWS @ COPYRIGHTS 2023