win.arguepatch


Actor(s): APT28, Sandworm

During a campaign against a Ukrainian energy provider, a new loader of a new version of CaddyWiper called "ArguePatch" was observed by ESET researchers. ArguePatch is a modified version of Hex-Ray's Remote Debugger Server (win32_remote.exe).
ArguePatch expects a decryption key and the file of the CaddyWiper shellcode as command line parameters.

ArguePatch CaddyWiper
ArguePatch CaddyWiper Industroyer INDUSTROYER2

There is no Yara-Signature yet.