Menu

  • Alerts
  • Incidents
  • News
  • APTs
  • Cyber Decoded
  • Cyber Hygiene
  • Cyber Review
  • Cyber Tips
  • Definitions
  • Malware
  • Threat Actors
  • Tutorials

Useful Tools

  • Password generator
  • Report an incident
  • Report to authorities
No Result
View All Result
CTF Hack Havoc
CyberMaterial
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
Hall of Hacks
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
No Result
View All Result
Hall of Hacks
CyberMaterial
No Result
View All Result
Home Incidents

Sandworm Wipers Hit Ukraines Grain Hub

November 6, 2025
Reading Time: 4 mins read
in Incidents
Belgian Telecoms Hit By Cyberattack

The Russian state-backed hacker group Sandworm has escalated its campaign of digital sabotage against Ukraine by deploying multiple data-wiping malware families against the country’s education, government, and the crucial grain sector, its main source of revenue. These destructive operations, which took place in June and September, continue Sandworm’s string of targeted attacks, also known as APT44, as detailed in a recent report by cybersecurity firm ESET. Unlike ransomware, which typically encrypts stolen data for ransom, a data wiper’s sole purpose is destruction, corrupting or deleting digital information like files and master boot records without the possibility of recovery, resulting in devastating and difficult-to-rebuild disruptions for the target. Since the invasion, Ukraine has faced numerous such campaigns, mostly attributed to Russian state-sponsored actors, including previously documented malware like PathWiper, HermeticWiper, and CaddyWiper.

ESET’s new analysis, covering APT activity from April to September 2025, highlights the deployment of various wipers in Ukraine, most notably the attacks targeting the nation’s grain production. This focus on a vital economic sector is a significant new development, indicating the attackers are attempting to weaken Ukraine’s ability to finance its war efforts, given that grain exports are a primary source of income. ESET reported that in June and September, Sandworm specifically utilized multiple malware variants against governmental, energy, logistics, and grain entities. While the other sectors have been hit since 2022, the concentration on the grain sector stands out as a clear effort to destabilize the country’s main economic pillar.

The APT44 group also deployed additional wipers named ‘ZeroLot’ and ‘Sting’ in April 2025, which were used to target a Ukrainian university. Interestingly, ‘Sting’ was executed via a Windows scheduled task named after the traditional Hungarian dish goulash. Researchers also observed that initial access for some of these incidents was first gained by another threat actor, UAC-0099, a group operating since at least 2023 and focused primarily on Ukrainian organizations, which then transferred that access to APT44 for the final deployment of the destructive wipers.

While Sandworm has recently dedicated more resources to espionage operations, the use of data wiper attacks against Ukrainian entities remains a persistent and continuous activity for the group. Furthermore, ESET also identified activity consistent with the tactics of Iranian-aligned hackers, though not attributed to a specific group. In a separate incident in June 2025, these clusters deployed Go-based tools derived from publicly available open-source wipers, targeting Israel’s energy and engineering sectors, underscoring the broader use of this destructive malware type by state-sponsored actors.

Fortunately, much of the guidance for defending against ransomware is also effective for mitigating data wiper attacks. The most critical step is maintaining offline backups of all critical data, ensuring they are physically or logically segregated and unreachable by hackers who gain network access. In addition, organizations should implement robust endpoint detection and intrusion prevention systems and diligently maintain all software updates, as these defenses can effectively prevent a wide range of attacks, including data wiping incidents.

Reference:

  • Sandworm Hackers Use Data Wipers To Disrupt Ukraines Grain Export Supply Chains
Tags: cyber incidentsCyber Incidents 2025Cyber threatsNovember 2025
ADVERTISEMENT

Related Posts

Belgian Telecoms Hit By Cyberattack

Hackers Steal Data From Swiss Bank

November 6, 2025
Belgian Telecoms Hit By Cyberattack

Belgian Telecoms Hit By Cyberattack

November 6, 2025

Hackers Target UK Water Suppliers

November 5, 2025

Nikkei Data Breach Hits 17000

November 5, 2025
Microsoft Edge Adds Scareware Sensor

Apache OpenOffice Denies Breach

November 5, 2025
Balancer Suffers 128 Million Exploit

Cybercriminals Exploit Remote Monitoring

November 4, 2025

Latest Alerts

Russia Group Exploits Windows HyperV

SkyCloak Backdoor Targets Defense Firms

Teams Bugs Let Hackers Impersonate

Post SMTP Plugin Hijacks Admins

React Native CLI Flaw Exposed

Smudged Serpent Targets US Experts

Subscribe to our newsletter

    Latest Incidents

    Hackers Steal Data From Swiss Bank

    Belgian Telecoms Hit By Cyberattack

    Sandworm Wipers Hit Ukraines Grain Hub

    Hackers Target UK Water Suppliers

    Nikkei Data Breach Hits 17000

    Apache OpenOffice Denies Breach

    CyberMaterial Logo
    • About Us
    • Contact Us
    • Jobs
    • Legal and Privacy Policy
    • Site Map

    © 2025 | CyberMaterial | All rights reserved

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In

    Add New Playlist

    No Result
    View All Result
    • Alerts
    • Incidents
    • News
    • Cyber Decoded
    • Cyber Hygiene
    • Cyber Review
    • Definitions
    • Malware
    • Cyber Tips
    • Tutorials
    • Advanced Persistent Threats
    • Threat Actors
    • Report an incident
    • Password Generator
    • About Us
    • Contact Us
    • Advertise with us

    Copyright © 2025 CyberMaterial