Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to malware
Malware

MeteorExpress

MeteorExpress is a wiper malware family referenced in reporting on Iranian disruptive and destructive cyber operations. The provided content identifies it as an example of wiper malware used in campaigns associated with Iranian state-aligned activity, alongside Shamoon. In that context, Iranian operations are described as targeting organizations in Israel, the United States, and allied nations, with likely affected sectors including government, critical infrastructure, defense, financial services, academic, and media. Anticipated destructive tradecraft in the same reporting includes deployment of wipers via fake hacktivist personas or APT clusters, exploitation of unpatched public-facing web services, and execution through scheduled tasks and LOLBins. The content does not provide specific technical indicators of compromise, infection-chain details, or platform-specific behavior for MeteorExpress beyond its classification as a wiper.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

MITRE ATT&CK

Techniques & procedures

1 distinct technique documented for this family, organized by ATT&CK tactic.

Impact

1 technique
T1485Data DestructionEvidence1

"Disruptive and destructive campaigns, notably wiper malware such as Shamoon and MeteorExpress"; "Deployment of wipers..."

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping1

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.