WhisperGate

MITRE
Malware Type:
Other
First seen:
Unknown
Last seen:
Unknown
Details:

[WhisperGate](https://attack.mitre.org/software/S0689) is a multi-stage wiper designed to look like ransomware that has been used against multiple government, non-profit, and information technology organizations in Ukraine since at least January 2022.(Citation: Cybereason WhisperGate February 2022)(Citation: Unit 42 WhisperGate January 2022)(Citation: Microsoft WhisperGate January 2022)

Associated Techniques (28)
ID ATT&CK Tactics
T1027.013 Encrypted/Encoded File -
T1036 Masquerading -
T1055.012 Process Hollowing -
T1059.001 PowerShell -
T1059.003 Windows Command Shell -
T1059.005 Visual Basic -
T1070.004 File Deletion -
T1071.001 Web Protocols -
T1083 File and Directory Discovery -
T1102 Web Service -
T1105 Ingress Tool Transfer -
T1106 Native API -
T1134.002 Create Process with Token -
T1135 Network Share Discovery -
T1140 Deobfuscate/Decode Files or Information -
Used by Actors (1)
Metadata
ID: 194
Created: 13/01/2026 17:48
Updated: 21/04/2026 16:00