CISA and the FBI warn that there is a possibility of data wiping attacks occurring in organizations in countries outside of Ukraine.
Specifically, the Cybersecurity and Infrastructure Security Administration (CISA) and the Federal Bureau of Investigation (FBI) have warned U.S. organizations that data wiping attacks targeting Ukraine could spread to targets in other countries. The two federal agencies issued this cybersecurity warning over the weekend following Russia’s unprovoked invasion of Ukraine.
See also: Ransomware that hit Ukraine is being used as bait

Although so far these attacks have only been deployed on Ukrainian networks, the actors deploying them could accidentally hit other targets, and American organizations should be prepared to prevent such devastating attacks.
Specifically, CISA and the FBI stated that further disruptive cyber malware attacks against organizations in Ukraine are likely to occur and may inadvertently spread to organizations in other countries. They also state that organizations should be vigilant and improve their capabilities that include planning, preparing, detecting and responding to such an event. The decision to warn was made after malware attacks against Ukraine using the HermeticWiper malware and “ransomware decoys” with the ultimate goal of destroying data and completely disabling devices.
CISA and FBI: Countering Data Wiping Attacks
The CISA and FBI post includes information on the HermeticWiper and WhisperGate and indicators of compromise (IOCs) to help organizations identify and block these types of malware. It also provides guidance and actions to take in the event of such incidents. Destructive malware can pose a direct threat to an organization’s day-to-day operations, impacting the availability of critical assets and data.
See also: Internal messages of the Conti ransomware gang leaked

The list of measures that organizations should take as an immediate defense against such attacks includes the following:
- Set up antivirus and malware protection programs to run regular scans
- Enable strong spam filters to prevent phishing emails
- Network traffic filtering
- Software update
- The introduction of the multi-factor authentication requirement element
A comprehensive list of potential distribution actors to monitor and block, as well as best practices and planning strategies, is at the end of the CISA and FBI post.
Source: bleepingcomputer.com
