AwfulShred
AwfulShred (canonical CERT-UA + industry naming per advisory 5850 January 27, 2023) is a Sandworm UAC- 0082 Linux Bash wiper deployed January 17, 2023 against Ukrainian state news agency Ukrinform as the Linux-targeting component of 5-wiper malware cocktail (CaddyWiper + ZeroWipe + SDelete on Windows + AwfulShred on Linux + BidSwipe on FreeBSD)
Russia GRU Unit 74455 Sandworm Team high-confidence attribution via CERT-UA canonical advisory 5850 with UAC-0082 = Sandworm tracking identity per Malwarebytes ("CERT-UA says it is confident the attack was carried out by the UAC-0082 group, which is its name for the Sandworm group") + Bleeping Computer ("CERT-UA linked the attack to the Sandworm threat group last week, a hacking outfit part of the Russian Military Unit 74455 of the Main Intelligence Directorate GRU") + ESET January 27 2023 SwiftSlicer parallel disclosure + Help Net Security + TechSpot + Dark Reading + SOC Prime industry coverage.
standalone cluster paralleling nikowiper + doublezero + roarbat in v0.1.151 Russia-aligned 2022-2023 destructive wiper operations cell.
operational target profile Ukrainian state news agency Ukrinform primary target January 17, 2023 + Linux systems specifically targeted by AwfulShred component within broader Windows + Linux + FreeBSD orchestrated 5-wiper malware cocktail + information communication system disruption objective + cluster-defining cyber-kinetic coordination with Yurii Shchyhol SSSCIP head press briefing delay about Russia hybrid warfare tactics ("The January cyberattack resulted in a delay of a press briefing by Yurii Shchyhol, head of the State Service of Special Communications and Information Protection, who intended to discuss Russia's use of hybrid warfare tactics")
operational attack architecture: (1) cluster-defining December 7, 2022 initial access + month-long dormancy APT tradecraft per Bleeping Computer + The Hacker News + Help Net Security ("the threat actors gained remote access to Ukrinform's network around December 7th and waited more than a month to unleash the malware cocktail"), signature Sandworm operational pattern.
(2) cluster-defining 5-wiper malware cocktail multi-platform strategy per CERT-UA + Bleeping Computer + TechSpot ("Sandworm has been busy since the Ukraine conflict... malware scripts targeted Windows, Linux, and FreeBSD systems and infected them with multiple malware payloads, including CaddyWiper, ZeroWipe, SDelete, AwfulShred, and BidSwipe") demonstrating Sandworm operational sophistication in orchestrated multi-platform destructive package tradecraft.
(3) signature Group Policy GPO deployment for CaddyWiper component within cocktail consistent with Sandworm pattern across v0.1.130 CaddyWiper April 2022 + v0.1.136 SwiftSlicer January 2023 + v0.1.151 RoarBAT April- May 2023.
(4) signature partial-success outcome with limited storage systems impact only per SSSCIP ("The wipers only managed to destroy files on 'several data storage systems,' which didn't impact Ukrinform's operations. The CERT-UA emphasizes that the cyberattack was only a partial success, specifically with regard to a limited number of data storage systems"), operationally significant defensive partial-mitigation despite sophisticated cocktail strategy.
(5) cluster- defining cyber-kinetic coordination press-briefing- disruption signature with destructive attack timed to delay Ukrainian official statement about Russia hybrid warfare campaign, characteristic of broader Russia-aligned cyber-information warfare coordination pattern.
cluster fills the January- 2023-onward + Linux-Bash-wiper + 5-wiper-malware- cocktail-component + Sandworm-UAC-0082-high- confidence-attribution + Ukrinform-state-news- agency-targeting + December-2022-initial-access + month-long-dormancy-APT-tradecraft + Ukrinform- partial-success-outcome + Yurii-Shchyhol-press- briefing-disruption position in Russia-aligned 2022-2023 destructive wiper operations cell; canonical illustration of 5-wiper malware cocktail multi-platform Sandworm strategy + Linux Bash wiper component capability + UAC-0082 = Sandworm tracking identity + dormant-access-then-deploy APT tradecraft + Ukrinform partial-success-outcome + Yurii Shchyhol SSSCIP press briefing cyber-kinetic coordination cited in essentially all subsequent destructive cyberweapon industry analyses through 2023-2026 period.