Skip to content

Malware

ArguePatch

During a campaign against a Ukrainian energy provider, a new loader of a new version of CaddyWiper called "ArguePatch" was observed by ESET researchers.

ArguePatch is a Windows malware family operated by APT28 and Sandworm.

Background

While investigating an operation aimed at a Ukrainian energy provider, ESET researchers spotted "ArguePatch," a fresh loader for a new build of CaddyWiper. ArguePatch is a tampered copy of Hex-Ray's Remote Debugger Server (win32_remote.exe). It takes a decryption key and the file containing the CaddyWiper shellcode as command-line arguments.


Source: Malpedia (Fraunhofer FKIE).