RU

DEV-0586DEV-0586

Also known as: Ruinous Ursa · Cadet Blizzard · DEV-0586

Origin
RU
Known aliases
3

Profile

MSTIC has not found any notable associations between this observed activity, tracked as DEV-0586, and other known activity groups. MSTIC assesses that the malware (WhisperGate), which is designed to look like ransomware but lacking a ransom recovery mechanism, is intended to be destructive and designed to render targeted devices inoperable rather than to obtain a ransom.

Aliases· 3

Ruinous UrsaCadet BlizzardDEV-0586

Known victims· 1

  • Ukraine

References

  1. https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/
  2. https://msrc-blog.microsoft.com/2022/02/28/analysis-resources-cyber-threat-activity-ukraine/
  3. https://unit42.paloaltonetworks.com/atoms/ruinousursa/
  4. https://www.microsoft.com/en-us/security/blog/2023/06/14/cadet-blizzard-emerges-as-a-novel-and-distinct-russian-threat-actor/
  5. https://www.microsoft.com/en-us/security/blog/2022/02/04/actinium-targets-ukrainian-organizations/

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
WhisperGate
Actor
Sunglow Blizzard
Actor
UAC-0185
Actor
DEV-0569
Actor
Storm-0558
Actor
UAT-8616
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.