Skip to content

Resources for DFIR Professionals Responding to the Whispergate

Notifications You must be signed in to change notification settings

cado-security/DFIR_Resources_Whispergate

Folders and files

NameName
Last commit message
Last commit date

Latest commit

author
chrisdoman
Jan 17, 2022
58742db · Jan 17, 2022

History

4 Commits
Jan 17, 2022
Jan 17, 2022
Jan 17, 2022
Jan 17, 2022

Repository files navigation

DFIR_Resources_Whispergate

On Saturday January 15th 2022, Microsoft released a blog titled “Destructive malware targeting Ukrainian organizations”. Microsoft’s blog outlines an ongoing attack against organisations in Ukraine by a currently-unknown threat actor and provides a detailed analysis of the malware samples involved.

We have provided additional resources below that may be of use to those responding or investigating the attacks:

  • Yara Rules
  • Copies of malware samples for detections. Do not run these unless you know how to safely analyse malware in a Virtual Machine!
  • Decompiled Source code, via RetDec and ILSpy