RoarBAT
RoarBAT (canonical CERT-UA + industry naming per April-May 2023 advisory with UAC-0165 moderate- confidence Sandworm attribution) is a Sandworm UAC- 0165-attributed WinRAR-based BAT script Windows wiper deployed April-May 2023 against an unnamed Ukrainian state agency, paired with Linux Bash + dd zero-byte companion wiper for multi-platform destruction.
Russia GRU Unit 74455 Sandworm Team moderate-confidence attribution via CERT-UA canonical advisory ("UAC-0165 with moderate confidence to the notorious Sandworm group aka FROZENBARENTS, Seashell Blizzard, or Voodoo Bear") + Ukrinform January 2023 UAC-0082 overlap evidence ("The method of implementation of the malicious plan, the IP addresses of the access subjects, as well as the fact of using a modified version of RoarBat testify to the similarity with the cyberattack on Ukrinform, information about which was published in the Telegram channel 'CyberArmyofRussia_Reborn' on January 17, 2023") + Bleeping Computer + SC Media + SOCRadar + Bitdefender + Govinfosecurity industry coverage; standalone cluster paralleling nikowiper + doublezero + awfulshred in v0.1.151 Russia-aligned 2022-2023 destructive wiper operations cell; operational target profile unnamed Ukrainian state agency primary target April-May 2023 per CERT-UA + critical systems via compromised VPN accounts without MFA + multi-platform Windows + Linux destruction.
operational attack architecture: (1) cluster-defining compromised VPN account without MFA initial access per CERT- UA + Bleeping Computer + SOCRadar ("Ukraine's critical systems have been accessed through compromised VPN accounts... The attackers accessed critical systems by exploiting VPN accounts lacking multi-factor authentication")
(2) cluster- defining WinRAR legitimate-archiver weaponization via -df command per The Hacker News + Bitdefender ("the use of a new batch script-based wiper malware called RoarBAT that performs a recursive search for files with a specific list of extensions and irrevocably deletes them using the legitimate WinRAR utility. This, in turn, was achieved by archiving the identified files using the '-df' command-line option and subsequently purging the created archives"), operationally innovative living-off-the-land tradecraft transforming defensive archiver into offensive destructive capability.
(3) signature 24+ file extensions comprehensive targeting per Bitdefender (.doc + .docx + .rtf + .txt + .xls + .xlsx + .ppt + .pptx + .vsd + .vsdx + .pdf + .png + .jpeg + .jpg + .zip + .rar + .7z + .mp4 + .sql + .php + .vbk + .vib + .vrb + .p7s + .sys + .dll + .exe + .bin + .dat) including documents + images + archives + backups (.vbk/.vib/.vrb Veeam backup signatures) + system files.
(4) cluster-defining Group Policy scheduled task deployment tradecraft per CERT-UA + SOCRadar consistent with Sandworm Group Policy Object deployment pattern (v0.1.130 CaddyWiper April 2022 + v0.1.136 SwiftSlicer January 2023); (5) cluster-defining Linux Bash + dd zero-byte companion wiper for multi-platform destruction ("The threat actors used a Bash script on Linux systems, which employed the 'dd' utility to overwrite target files with zero bytes, making file recovery unlikely or impossible")
(6) cluster-defining Ukrinform UAC-0082 - UAC-0165 Sandworm attribution chain with three converging indicators (IP addresses + implementation method + modified RoarBat version) tying RoarBAT April-May 2023 attack to January 2023 Ukrinform attack and through that to Sandworm operations.
cluster fills the April-May-2023-onward + WinRAR-weaponization + Group-Policy-scheduled-task + compromised-VPN-no- MFA-initial-access + multi-platform-Windows-Linux + Sandworm-UAC-0165-Ukrinform-overlap position in Russia-aligned 2022-2023 destructive wiper operations cell.
canonical illustration of WinRAR legitimate-program weaponization + GPO scheduled task Sandworm deployment pattern + compromised VPN no-MFA initial access + multi-platform Linux dd companion wiper + Ukrinform UAC-0082 - UAC-0165 Sandworm attribution chain cited in essentially all subsequent destructive cyberweapon industry analyses through 2023-2026 period.