Meteor is a destructive Windows file-wiping malware first publicly reported by SentinelOne in connection with the July 2021 disruption of Iran’s railway system. The malware was described as previously unseen and specifically built to delete data. Public reporting cited in the content also links Meteor to the 2021 railway system disruption, and broader reporting places it among Iran-related destructive malware families alongside ZeroCleare, Dustman, and Apostle.
Observed behavior in the provided content shows Meteor using multiple defense evasion and impact techniques. It can search for Kaspersky Antivirus on a victim machine, attempt to uninstall Kaspersky or remove its license, and add attack-related files and folders to the Windows Defender exclusion list. It can hide its console window during execution to reduce user visibility. For anti-recovery and destructive effect, it can disable network adapters via PowerShell, delete shadow copies using vssadmin.exe and C:\Windows\system32\wbem\wmic.exe shadowcopy delete, use wmic.exe as part of shadow copy deletion, and use bcdedit to delete boot identifiers. It can also clear Security, System, and Application event logs with wevtutil.
Meteor’s payload behavior includes overwriting files and directories with zero bytes before deleting them. It can also modify user-facing system elements by changing the desktop wallpaper and lock screen image to a custom image. Execution has been observed beginning from a scheduled task, including a task named Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeAll, and creating a separate scheduled task named mstask to run the wiper once at 23:55:00.
High-confidence indicators and artifacts directly mentioned in the content include use of PowerShell to disable network adapters; wevtutil for log clearing; vssadmin.exe delete shadows /all /quiet; C:\Windows\system32\wbem\wmic.exe shadowcopy delete; bcdedit for boot configuration deletion; Kaspersky-focused checks and uninstall activity; Windows Defender exclusion additions; and the scheduled task name mstask.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Shamoon 4.0 and Meteor are the primary destructive payloads assessed as active in the current conflict cycle.
"...including the 2021 railway system disruption using the Meteor wiper..."
21 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware using WMI/WMIC/wmiexec for remote execution, lateral movement, discovery, persistence, and administrative actions; e.g., 'APT41 used WMI in several ways, including for execution of commands via WMIEXEC as well as for persistence via PowerSploit' and 'Scattered Spider used Windows Management Instrumentation (WMI) to move laterally via Impacket.'
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.
The content repeatedly describes threat actors and malware using PowerShell scripts/commands for execution, download, staging, reconnaissance, persistence, credential access, lateral movement, and defense evasion; e.g., "Sandworm Team used PowerShell scripts to run a credential harvesting tool in memory to evade defenses."
APT1 has used the Windows command shell to execute commands, and batch scripting to automate execution. Blue Mockingbird has used batch script files to automate execution and deployment of payloads. During HomeLand Justice, threat actors used Windows batch files for persistence and execution.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“APT28 has cleared event logs, including by using the commands wevtutil cl System and wevtutil cl Security …” / “APT38 clears Window Event logs and Sysmon logs …” / “BlackCat can clear Windows event logs using wevtutil.exe …” / “NotPetya uses wevtutil to clear the Windows event logs …”
The content repeatedly describes threat actors and malware deleting files, tools, scripts, logs, droppers, staged data, and artifacts from compromised systems to cover tracks, remove evidence, or self-delete.
Several entries describe malware examining running processes to determine if a debugger, sandbox, virtual environment, or analysis/security tools are present, such as AsyncRAT checking for a debugger, RogueRobin enumerating Wireshark and Sysinternals processes, and P8RAT checking for processes associated with virtual environments.
The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
Several entries describe malware examining running processes to determine if a debugger, sandbox, virtual environment, or analysis/security tools are present, such as AsyncRAT checking for a debugger, RogueRobin enumerating Wireshark and Sysinternals processes, and P8RAT checking for processes associated with virtual environments.
Research from cybersecurity company SentinelOne revealed that Iran’s train station system was targeted with malware specifically built to delete data (file wiper) called Meteor that had not been seen before.
"Play has used Base64-encoded PowerShell scripts to disable Microsoft Defender," "StrongPity can use PowerShell to add files to the Windows Defender exclusions list," and "ZeroCleare can use a malicious PowerShell script to bypass Windows controls."
Examples include 'Aquatic Panda has attempted to stop endpoint detection and response (EDR) tools', 'BlackByte disabled security tools such as Windows Defender', 'Scattered Spider has uninstalled and disabled security tools', and many malware families terminating AV/EDR processes or services.
BlackByte Ransomware 'adds .JS and .EXE extensions to the Microsoft Defender exclusion list'; PureCrypter 'executed Set-MpPreference -ExclusionPath'; QakBot 'modify the Registry to add its binaries to the Windows Defender exclusion list'; Raspberry Robin 'add an exception to Microsoft Defender that excludes the entire main drive'; StrongPity 'add directories used by the malware to the Windows Defender exclusions list'; XLoader 'can add the path of its executable to the Microsoft Defender exclusion list'; ZIPLINE 'can add itself to the exclusion list for the Ivanti Connect Secure Integrity Checker Tool.'
30 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A destructive payload assessed as active in the current conflict cycle.
An Iran-linked wiper malware family referenced as part of a deliberate arsenal intended for destructive attacks and operational disruption.
Destructive wiper malware family referenced as part of Iran-aligned wiper tooling.
Custom wiper used in sabotage operations attributed to Predatory Sparrow/Gonjeshke Darande, including disruption of Iranian railway systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.