DoubleZero
DoubleZero (canonical CERT-UA naming per March 22, 2022 advisory with UAC-0088 tracking) is a C#/.NET obfuscated Windows wiper deployed March 17, 2022 against Ukrainian enterprises via spearphishing ZIP archive delivery (one archive named "Virus ... extremely dangerous !!!.zip" per CERT-UA); important attribution caveat, CERT-UA tracks DoubleZero under UAC-0088 identifier DISTINCT from Sandworm UAC-0082 (Ukrinform January 2023) + UAC-0165 (RoarBAT April-May 2023), placing DoubleZero within Russia-aligned 2022 destructive operations ecosystem but operationally distinct from Sandworm Team per CERT-UA + ESET wiper-year-review tracking (which includes DoubleZero in 2022 Ukraine wiper timeline without explicit Sandworm attribution); Russia-aligned destructive operations attribution via CERT-UA canonical March 22 2022 advisory ("The activity is tracked by the UAC-0088 identifier and is directly related to attempts to violate the regular mode of operation of information systems of Ukrainian enterprises") + Acronis canonical technical analysis + SOC Prime + eSentire TRU detailed malware analysis + Council on Foreign Relations Russia-Ukraine war cyber operations tracking + BlackBerry Russian Wrecking Crews compilation.
standalone cluster paralleling nikowiper + roarbat + awfulshred in v0.1.151 Russia-aligned 2022-2023 destructive wiper operations cell.
operational target profile Ukrainian enterprises primary target March 2022 per CERT-UA + signature cluster-defining domain controller exclusion preserving DC for potential follow-on operations.
operational attack architecture: (1) cluster-defining spearphishing ZIP archive delivery with distinctive "Virus ... extremely dangerous !!!.zip" payload naming tradecraft per CERT-UA.
(2) cluster-defining C#/.NET obfuscated codebase distinguishing from typical C/C++ Sandworm wiper signatures (CaddyWiper + HermeticWiper + NikoWiper) per Acronis ("DoubleZero, although written in .NET, is obfuscated, another technique to make it difficult for researchers to inspect further. After de- obfuscation, the wiper functionality can be divided into three parts: host reconnaissance, permission modification and wiping")
(3) cluster-defining dual-mode zeroing mechanism per CERT-UA + SOC Prime ("It erases files in one of two ways: overwriting files with zero blocks of 4096 bytes (FileStream.Write method) or using NtFileOpen, NtFsControlFile API calls (code: FSCTL_SET_ZERO_DATA)") , first mechanism uses standard file-stream zero- block overwrite, second uses NTFS sparse-file API for efficient zero-data signaling.
(4) cluster- defining domain controller exclusion per Acronis ("This malware does not run on domain controllers, and it checks for the host's role within the network. If the host is a domain controller, the malware terminates but does not wipe itself off the system"), operationally significant DC preservation for potential follow-on operations or intelligence collection.
(5) cluster-defining UAC-privilege- dependent adaptive scope per eSentire ("The executables need to be run as an Administrator for it to gain the full access to the system files and registry keys to proceed with deletion/wiping process. If the executables are opened as a user without UAC privilege elevation - the malware only wipes the files under C:\Users and the system shuts down after")
(6) signature LSASS termination OR manual shutdown completion behavior per Acronis adaptive shutdown completion tradecraft; (7) registry branch destruction extending beyond file destruction per CERT-UA.
cluster fills the March-2022-onward + C#/.NET-codebase + UAC-0088- separate-tracking + spearphishing-ZIP-delivery + dual-mode-zeroing + DC-exclusion + UAC-dependent- scope position in Russia-aligned 2022-2023 destructive wiper operations cell with honest attribution caveat preserving analytic clarity; canonical illustration of 2022 Ukraine destructive- wiper-landscape diversity + CERT-UA UAC-0088 separate-from-Sandworm tracking taxonomy + C#/.NET wiper codebase variant + dual-mode zeroing mechanism + DC-exclusion + UAC-privilege-dependent adaptive scope cited in essentially all subsequent destructive cyberweapon industry analyses of the 2022 Ukraine wiper landscape through 2022-2026 period.