DEV-0586 (Ruinous Ursa) is known for destructive fake ransomware attacks using WhisperGate against Ukraine.
Analyst brief
DEV-0586 (Ruinous Ursa, Cadet Blizzard) is a destructive cyber threat actor primarily targeting entities in Ukraine. It utilizes WhisperGate malware, which masquerades as ransomware but lacks any ransom recovery mechanism, aiming instead to render targeted devices inoperable. Defenders should focus on detecting signs of destructive wiper attacks disguised as ransomware and ensure critical system backups are robust and offline to mitigate impact.
DEV-0586
Ruinous UrsaCadet Blizzard
unknown
MSTIC has not found any notable associations between this observed activity, tracked as DEV-0586, and other known activity groups. MSTIC assesses that the malware (WhisperGate), which is designed to look like ransomware but lacking a ransom recovery mechanism, is intended to be destructive and designed to render targeted devices inoperable rather than to obtain a ransom.
What is the objective of the DEV-0586 (Ruinous Ursa) group's use of WhisperGate malware?+
WhisperGate masquerades as ransomware but is designed to be destructive, lacking any ransom recovery mechanism. The intent is to render targeted devices inoperable rather than to obtain a ransom.
What protective measures should be taken against the destructive attacks of the DEV-0586 actor?+
Defenders should focus on detecting signs of destructive wiper attacks disguised as ransomware and ensure critical system backups are robust and offline.