ZEROLOT is a destructive data-wiping malware family associated with the Russia-aligned Sandworm threat group (also tracked as APT44, Voodoo Bear, Iron Viking, Telebots, and Seashell Blizzard). Reporting in the provided content links ZEROLOT to Sandworm operations against Ukrainian targets in 2024–2025, including a Ukrainian university and organizations in the government, energy, logistics, telecom, and grain sectors. Multiple sources in the content describe the malware as a wiper intended to permanently erase data and disrupt operations, with attacks framed as part of broader destructive campaigns against Ukraine’s critical infrastructure and economy. The content states that Sandworm deployed ZEROLOT via Active Directory Group Policy, and in one April 2025 university intrusion the deployment was executed using a Windows scheduled task named DavaniGulyashaSdeshka. ZEROLOT is repeatedly mentioned alongside another Sandworm wiper, Sting. High-confidence context in the content places ZEROLOT among Sandworm’s broader set of destructive malware families, alongside PathWiper and HermeticWiper. No file hashes or standalone technical IoCs specific to ZEROLOT are provided in the content beyond the scheduled task name DavaniGulyashaSdeshka and the reported use of Active Directory Group Policy for deployment.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Indicators of Compromise (IoCs):- ... Malware ZEROLOT Wiper malware linked to Sandworm
1 distinct technique documented for this family, organized by ATT&CK tactic.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Wiper malware linked to Sandworm.
Destructive malware family referenced as used in wiper attacks.
Data-wiping malware used by Sandworm in a Ukrainian university network.
ZEROLOT is a destructive data wiper malware used by the Sandworm group to target Ukrainian organizations, aiming to destroy data and disrupt operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.