Microsoft is warning about a data-wiping malware masquerading as ransomware and being used in attacks against multiple organizations in Ukraine. Since January 13, Microsoft has detected attacks that combine a destructive MBRLocker with data-corrupting malware that destroys the victim's data.

Two-stage attack
Microsoft calls this new malware family, “WhisperGate,” and explains that the attack is carried out via two different destructive malware components.
The first component, called stage1.exe, starts from the C:\PerfLogs, C:\ProgramData, C:\, or C:\temp folders, which replaces the Master Boot Record to display a ransom note (which is why it looks like ransomware).
See also: Dark web: Carding platform UniCC closes its store
MBR locker is a program that replaces the “master boot record,” a location on a computer's hard drive that contains information about disk partitions and a small executable file used to load the operating system.
MBR lockers replace the boot loader in the master boot record with a program that typically encrypts the partition table and displays a ransom note. This prevents the operating system from loading and data from being accessed until the ransom is paid.
The WhisperGate ransom note, in one of the attacks Microsoft detected, tells the victim to send $10,000 in bitcoin to the address 1AVNM68gj6PGPFcJuftKATa4WLnzg8fpfv and to contact the attackers via a Tox chat ID.
Microsoft says that the use of Tox indicates that this is not a regular ransomware. However, BleepingComputer says that there are ransomware groups that use Tox as a method of communication.
However, the MBRLocker ransom note uses the same bitcoin address for all victims and does not provide a method to enter a decryption key. This usually indicates that this is not true ransomware, but data-wiping malware designed for destructive purposes.
The second component, called stage2.exe, runs simultaneously with the first to download a data-destroying malware called Tbopbh.jpg. It is hosted on Discord and replaces targeted files with static data.
See also: Microsoft Defender vulnerability prevents malware detection
“If a file has one of the following extensions, the malware replaces the file contents with a fixed number of 0xCC bytes (total file size 1MB),” Microsoft’s report explains.
.3DM .3DS .7Z .ACCDB .AI .ARC .ASC .ASM .ASP .ASPX .BACKUP .BAK .BAT .BMP .BRD .BZ .BZ2 .CGM .CLASS .CMD .CONFIG .CPP .CRT .CS .CSR .CSV .DB .DBF .DCH .DER .DIF .DIP DOC .LDF .LOG .MAX .MDB .MDF .MML .MSG .MYD .MYI .NEF .NVRAM .ODB .ODG .ODP .ODS .ODT .OGG .ONETOC2 .OST .OTG .OTP .OTS .OTT .P12 .PAQ .PAS .PDF .PEM .PFX .PHP .PHP3 .PHP4 .PHP5 .PHP6 .PHP7 .PHPS .PHTML .PL .PNG .POT .POTM .POTX .PPAM .PPK .PPS .PPSM .PPSX .PPT .PPTM .PPTX .PS1 .PSD .PST .PY .RAR .RAW .RB .RTF .SAV .SCH .SHTML .SLDM .SLDX .SLK .SLN .SNT .SQ3 .SQL .SQLITE3 .SQLITEDB .STC .STD .STI .STW .SUO .SVG .SXC .SXD .SXI .SXM .SXW .TAR .TBK .TGZ .TIF .TIFF .TXT .UOP .UOT .VB .VBS .VCD .VDI .VHD .VMDK .VMEM .VMSD .VMSN .VMSS .VMTM .VMTX .VMX .VMXF .VSD .VSDX .VSWP .WAR .WB2 .WK1 .WKS .XHTML .XLC .XLM .XLS .XLSB .XLSM .XLSX .XLT .XLTM .XLTX .XLW .YML .ZIP“After replacing the contents, the malware renames each file with a seemingly random four-byte extension“.
As neither malware component offers a means to import decryption keys, restore the original Master Boot Record, and as files are replaced with static undecryptable data, Microsoft believes these are attacks that use this malware to destroy files and not to extract money from hackers.

Microsoft has not been able to link the attacks to any specific group.
With geopolitical tensions escalating between Russia and Ukraine, it is believed that these alleged ransomware attacks are designed to create chaos in Ukraine.
See also: Ransomware gang that affected over 50 companies arrested
A similar attack took place in 2017, when thousands of businesses in Ukraine were targeted by the NotPetya. NotPetya was based on a real ransomware, known as Petya. However, those attacks on Ukraine were also not aimed at ransom.
Ukraine: Target of cyberattacks in recent days
Last week, several websites of public institutions and government agencies in Ukraine were hacked and taken offline.
The defacement attacks resulted in the display of a message warning site visitors that their data had been stolen and shared publicly on the internet.
However, threat actors who have examined the published data say it is not related to Ukrainian government agencies but to data from an old leak.
Ukraine blames Russia for the attacks.
Source: Bleeping Computer
