A new type of malware has been detected, named Azov Wiper or Azon Ransomware, which destroys data at an unimaginable rate!
Wiper malware is the latest form of malware that is rapidly gaining ground among cybercriminals. It targets computers and servers, deleting data efficiently and quickly, leaving no chance of recovery. The Azov ransomware is an example of wiper malware, destroying 666 bytes of data at a time.
On Monday, Check Point Research unveiled Azov Wiper – a fast and powerful data sanitization program that unfortunately cannot be recovered. It does this by overwriting files in blocks of 666 bytes with random data, while leaving a block of the same size untouched. In the process, it uses the uninitialized local variable char buffer[666]. Impressive and disturbing at the same time!
See also: APT37 group uses an Internet Explorer zero-day and spreads malware
After destroying data on affected computers, Azov Wiper displays a note with content similar to that of other ransomware announcements . This threatening message specifically echoes sentiments from the Kremlin regarding the ongoing war against Ukraine and allegedly threatens nuclear strikes. According to one of the two samples recovered by Check Point , this threatening text was falsely attributed to a prominent malware analyst originating from Poland.

Despite the young age of its creators, Azov is a highly sophisticated virus. It meets the original definition of a computer virus, as it modifies files by adding polymorphic code to 64-bit backdoor executables and attacks the infected system. Assembly , a complex but efficient low-level language, was used to write this malware , which makes backdooring more successful. In addition, Azov Wiper uses various methods such as polymorphic code to make detection and analysis more difficult than usual for security researchers.
Check Point researcher Jiri Vinopal noted that while the Azov Wiper sample was initially considered skidsware , as more research was conducted, it became apparent that it used very advanced techniques – including manual assembly creation , the use of payloads in executable files for back-dooring purposes , and anti-analysis tricks typically found in security books or notoriously branded cybercrime tools. He concluded by stating that the Azov ransomware should definitely present an increased level of difficulty compared to other malware samples they have encountered.
See also: Rackspace warns of rise in phishing attacks
Azov is no ordinary malware. Programmed with a logic bomb, it explodes when the pre-set time is reached and wipes out every file directory except those specified by its hard-coded system paths and extensions. With over 17,000 backdoored executables reported to VirusTotal last month, this insidious malware is well on its way to becoming widespread across cyberspace.

Last Wednesday, ESET security researchers uncovered two new devastating malware programs dubbed Fantasy and Sandals . The malware spread via a supply chain attack that exploited the infrastructure of an Israeli software company used in the diamond industry. In less than three hours, Fantasy and Sandals infiltrated clients connected to human resources services, IT support services, and diamond wholesale businesses based in South Africa, Israel, and Hong Kong. Azov Wiper could have infiltrated just as easily .
Drawing on Apostle code , Fantasy initially appeared as ransomware before being revealed to be a wiper . Furthermore, the reuse of code led ESET to believe that both Fantasy and Sandals had ties to Agrius – an Iran-based group located in the Middle East.
While we cannot pinpoint the exact motive behind this malware, it is safe to assume that none of the people or organizations mentioned in the ransom note had any involvement in its creation. We must make it clear that no good intentions were evident when creating this ransomware. If someone were to simply assume that it is the result of an unstable individual, they would be right. However, if someone wanted to intentionally use it to incite anger against Ukraine and cause more damage to its victims, there is ample evidence of this. The number of Azov Wiper that have already been detected has multiplied so much that any initial target could have been covered by random infections long ago.
Source: arstechnica.com
