Skip to content

Malware

DesertBlade

According to Microsoft, this was used in a limited destructive malware attack in early March 2022 impacting a single Ukrainian entity.

DesertBlade is a Windows malware family.

Background

Microsoft reports that this was deployed in a narrowly scoped destructive attack in early March 2022 against a single Ukrainian organization. DesertBlade works by repeatedly overwriting files and then deleting the overwritten copies across every reachable drive, while leaving the host untouched if it is a domain controller.


Source: Malpedia (Fraunhofer FKIE).