Desk live·
ForensicPost
Nation-state/Infrastructure/File 22-0114

WhisperGate Wiper Hit Ukrainian Government Sites Six Weeks Before the Invasion

WhisperGate destroyed the master boot record on Ukrainian government systems and left an extortion message behind. There was no recovery mechanism, because recovery was never the point — the note was camouflage, six weeks before the invasion.

Constructed geometry · not a chart of case data
JurisdictionUkraineKyivthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetUkrainian government organisations
ActorUnattributed
S. Rosler11 min readConfidence: high3 sources reviewed

WhisperGate appeared on systems in Ukraine from 13 January 2022, alongside the defacement of Ukrainian government websites on 14 January. Ukraine’s security service reported at least 70 government sites targeted.

Microsoft assessed the malware as designed to look like ransomware while lacking any ransom recovery mechanism — intended to render devices inoperable rather than to extract payment. It overwrites the master boot record. Microsoft tracked the activity as DEV-0586 and reported no notable association with known groups at the time; Symantec subsequently attributed the campaign to a Russia-linked actor. CISA later warned the malware could spill beyond Ukraine.

The Note Was The Disguise

A ransomware note costs nothing to write and buys something valuable: an initial reading. An organisation that finds one begins a recovery conversation — decryption, negotiation, insurance — rather than an incident-response conversation about who is inside the network and why.

We have recorded the same technique at 22-0715, where a ransomware family accompanied a wiper against Albanian government systems, and at 22-0224. Misdirection is not an accident of these operations; it is a deliverable, and it works on the first day, which is the day that matters most.

The Master Boot Record Is Not Data

Overwriting the boot record does not steal anything and does not encrypt anything. It makes the machine fail to start.

No disclosure regime in this corpus has a field for that. We have argued at 24-1231 and 22-0224 that availability harm is invisible to breach reporting, and this is the purest form: nothing was taken, nothing was ransomed, and a government lost the use of its systems six weeks before it needed them most.

Attribution Was Not Available At The Time

Microsoft published without linking the activity to a known group. Attribution came later, from a different vendor, on a different basis.

The desk records this because the corpus grades attribution separately from events throughout, and this file is a clean example of why. On 15 January the honest statement was "destructive malware, actor unknown", and a defender who waited for a name before acting would have waited weeks.

How we reported this

Compiled from Microsoft’s January 2022 analysis, CISA’s advisory and contemporaneous reporting, listed below. The later attribution to a Russia-linked actor is Symantec’s and is carried as a researcher assessment rather than as established fact; no state is named as responsible by this desk. No indicators or samples are reproduced. Graded high on the event and the malware’s character. Corrections: corrections@forensicpost.com.

Sources
  1. Destructive malware targeting Ukrainian organizationsMicrosoft Security
  2. Update: Destructive Malware Targeting Organizations in Ukraine (AA22-057A)CISA
  3. Microsoft Uncovers Destructive Malware Used in Ukraine CyberattacksSecurityWeek
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary