August 7, 2019 By David Bisson < 1 min read

Researchers spotted a new malware family called GermanWiper that masquerades as ransomware but destroys affected data even when victims pay the ransom.

Bleeping Computer first learned of GermanWiper on July 30 when victims began posting about it on the site’s forums. According to the researchers, the malware began by leaving a ransom note prompting the victim to pay 0.15038835 bitcoins for a decryption key. But the sample they analyzed didn’t encrypt the victim’s data. Instead, it overwrote each file’s data with ones and zeroes, effectively destroying its contents.

According to Bleeping Computer, digital attackers distributed GermanWiper primarily in Germany through a spam campaign. The attack email masqueraded as a job application from a person named Lena Kretschmer. It contained an attachment named Unterlagen_Lena_Kretschmer.zip, which carried malicious PDF documents that downloaded the malware’s executable via a PowerShell command.

More Wiper Malware Disguised as Ransomware

Data wipers have been assuming ransomware as a disguise for years. In June 2017, IBM X-Force Incident Response and Intelligence Services (IRIS) analyzed the international outbreak of NotPetya malware and concluded that attackers were not financially motivated; they aimed simply to destroy data.

Just a few months later, SpamTitan reported on Ordinypt, another wiper family that targeted Germany posing as ransomware. Just a few months after that, Cisco Talos observed how some variants of LockerGoga were effectively preventing users from logging back onto their infected systems following the encryption process, thus rendering their infections destructive.

Defend Your Data Against GermanWiper

Security professionals can help defend against GermanWiper by using an endpoint management solution to provide visibility into the company’s assets and help streamline the process of patching known vulnerabilities. Security teams should also employ a layered defense strategy that draws on antimalware solutions, security awareness training and data backups to defend against destructive malware attacks.

More from

Quishing: A growing threat hiding in plain sight

4 min read - Our mobile devices go everywhere we go, and we can use them for almost anything. For businesses, the accessibility of mobile devices has also made it easier to create more interactive ways to introduce new products and services while improving user experiences across different industries. Quick-response (QR) codes are a good example of this in action and help mobile devices quickly navigate to web pages or install new software by simply scanning an image.However, legitimate organizations aren’t the only ones…

Cybersecurity Awareness Month: 5 new AI skills cyber pros need

4 min read - The rapid integration of artificial intelligence (AI) across industries, including cybersecurity, has sparked a sense of urgency among professionals. As organizations increasingly adopt AI tools to bolster security defenses, cyber professionals now face a pivotal question: What new skills do I need to stay relevant?October is Cybersecurity Awareness Month, which makes it the perfect time to address this pressing issue. With AI transforming threat detection, prevention and response, what better moment to explore the essential skills professionals might require?Whether you're…

Why safeguarding sensitive data is so crucial

4 min read - A data breach at virtual medical provider Confidant Health lays bare the vast difference between personally identifiable information (PII) on the one hand and sensitive data on the other.The story began when security researcher Jeremiah Fowler discovered an unsecured database containing 5.3 terabytes of exposed data linked to Confidant Health. The company provides addiction recovery help and mental health treatment in Connecticut, Florida, Texas and other states.The breach, first reported by WIRED, involved PII, such as patient names and addresses,…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today