The Russian state-sponsored hacking group Sandworm, also known as APT44, has launched new waves of attacks against government, educational, and financial targets in Ukraine, using multiple data wiper malware. According to a recent report by ESET, the attacks took place between June and September 2025, as part of a broader digital warfare strategy aimed at destabilizing the Ukrainian economy.

What are “data wipers” and why are they so dangerous
Unlike ransomware, which encrypts data for the purpose of financial extortion, data wipers are designed to completely destroy digital files .
This software deletes data, disk partitions, and boot files, making information recovery virtually impossible. The goal is not profit, but sabotage – creating chaos, disrupting critical functions, and weakening the victim’s resilience.
See also: Dismantling a major credit card fraud operation
ESET warns that recent Sandworm attacks have caused severe business disruptions , particularly in the grain sector , one of the most critical pillars of the Ukrainian economy.
Targeting the cereals sector – Attack on Ukraine's economy
Ukraine is one of the world's largest grain exporters. During the war, these exports were a vital source of income for the country, largely financing its war economy.
According to ESET, Sandworm allegedly developed multiple variants of malware against companies in the agro-industrial sector, seeking to paralyze the supply chain and disrupt the distribution of grain inside and outside Ukraine.
Although in the past the group had targeted energy and government infrastructure, the shift to economic targets suggests a strategic shift: Russia now seeks to strike the country not only on the battlefield, but also at its economic underpinnings.

New malicious tools: ZeroLot and Sting
The report reveals two new malware programs deployed in April 2025 — ZeroLot and Sting. The former was designed to delete files with targeted precision, while the latter was executed via scheduled Windows tasks, indicating a high level of technical expertise.
See also: Cl0p Ransomware Exploits New 0-Day Vulnerabilities
For example, Sting used misleading process names, such as one referring to Hungarian food (“goulash”), to avoid raising suspicions among victims. The target of these attacks was a Ukrainian university, indicating that Sandworm is not limited to government organizations, but also seeks to target the education and research.
The «shadows» behind Sandworm: UAC-0099 and international collaborations
The ESET report reveals that in several cases, initial access to the victims’ networks was gained by the UAC-0099, which then handed over the access credentials to Sandworm to execute the attacks. UAC-0099 has been active since at least 2023 and primarily targets Ukrainian government agencies.
ESET points out that, despite Sandworm's shift in recent years towards more "discreet" espionage operations, data deletion attacks remain a key element of its tactics.

The global threat of data wipers and defense methods
The data wiper phenomenon is no longer limited to governments at war, but also affects businesses worldwide. Experts recommend that companies maintain backups on isolated media, disconnected from production networks, to avoid losing critical data.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Equally important is keeping all systems up to date, implementing strong authentication policies, and using detection and prevention tools intrusion (EDR/IDS) that can identify suspicious behavior before malware spreads.
See also: SonicWall: State-sponsored hackers behind September breach
The digital war continues
The Sandworm case is a reminder that cyberwarfare is now an integral part of modern conflicts. Ukraine, as a battlefield both physical and digital, remains at the forefront of a new era, where data has become a target as valuable – and vulnerable – as territory.
Source: www.bleepingcomputer.com
