Skip to main content
Mallory
Back to malware
MalwareUsed by 2 actors

Wiper malware

Wiper malware is data-destroying malware referenced in multiple incidents involving destructive cyber operations. In the provided content, it is described as being used to target financial data on victim systems in the Bank Sepah case, where branch, ATM, online, and in-branch banking services were disrupted, and in attacks against OT/ICS environments where attackers gained initial access through vulnerable or misconfigured internet-facing edge devices and then deployed wiper malware while compromising remote terminal units (RTUs). Reported OT impacts included reduced visibility between facilities and distribution system operators, corrupted human-machine interface (HMI) data, corrupted OT device firmware, and damage to RTUs. The content also describes a recurring Iranian playbook in which Microsoft-assessed MOIS-linked Storm-861 gains access and Storm-842 later deploys wiper malware, observed in Albania in 2022 and again in Israel in late October 2023. Separately, Mandiant reported that Russia’s GRU used edge-device compromises to enable rapid follow-on wiper attacks in Ukraine, including repeated destructive attacks against the same organizations while sometimes retaining access through compromised firewalls, routers, email servers, or Zimbra infrastructure. Sectors and environments explicitly mentioned as affected by wiper malware in the content include finance, government, media, telecom, energy, and distributed energy/critical infrastructure OT. Associated actors mentioned in connection with wiper malware include Predatory Sparrow in the Bank Sepah context, Microsoft-tracked MOIS-linked groups Storm-842 and Storm-861, and Russian state actors including GRU activity and the Poland energy-sector intrusion attributed in reporting to Static Tundra/Berserk Bear/Dragonfly/Ghost Blizzard, with other reporting also citing Sandworm/Electrum assessments. Infection vectors explicitly mentioned include exploitation or abuse of vulnerable internet-facing edge devices, compromised firewalls, routers, email servers, ProxyShell exploitation of Microsoft Exchange, and use of stolen credentials for Zimbra access.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Predatory Sparrow

It appears that in both cases, the operations targeted the financial data resident on the targeted systems and not the functionality of the systems themselves (although ATM and on-line and in-branch services were disrupted), likely with the use of wiper malware in the Bank Sepah case...

via lieber westpointlieber.westpoint.edu
Dragonfly

"...enabled attackers to launch wiper malware and compromise remote terminal units..."

via scworldscworld.com
MITRE ATT&CK

Techniques & procedures

11 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

4 techniques
T1078.001Default AccountsEvidence1

“Threat actors leveraged default credentials… to pivot onto the HMI and RTUs.”

T1190Exploit Public-Facing ApplicationEvidence2

“A malicious cyber actor(s) gained initial access in this incident through vulnerable internet-facing edge devices…”

T1195Supply Chain CompromiseEvidence1

After a few hours, the hackers accessed another server that delivered software updates to the modems – which allowed them to deliver the wiper malware

T1566PhishingEvidence1

Dr. Al Kuwaiti noted that phishing emails, once easily identifiable by poor grammar, are now flawlessly written using AI. These emails often exploit current events to trick users into clicking malicious links, which then deploy ransomware or “wiper” malware.

Execution

1 technique
T1203Exploitation for Client ExecutionEvidence1
TacticExecution

These emails often exploit current events to trick users into clicking malicious links, which then deploy ransomware or “wiper” malware.

Persistence

1 technique
T1078.001Default AccountsEvidence1

“Threat actors leveraged default credentials… to pivot onto the HMI and RTUs.”

T1078.001Default AccountsEvidence1

“Threat actors leveraged default credentials… to pivot onto the HMI and RTUs.”

Stealth

1 technique
T1078.001Default AccountsEvidence1

“Threat actors leveraged default credentials… to pivot onto the HMI and RTUs.”

Impact

6 techniques
T1485Data DestructionEvidence12
TacticImpact

CERT Polska detailed coordinated destructive cyberattacks on more than 30 wind, solar, and combined heat and power (CHP) facilities in Poland... where attackers used wiper malware... to disrupt communications and OT systems.

T1489Service StopEvidence1
TacticImpact

Predatory Sparrow targeted Bank Sepah, Iran’s oldest and largest bank, causing branch closures and widespread service outages with customers unable to access accounts, withdraw cash, or use bank cards for some undetermined amount of time.

T1495Firmware CorruptionEvidence1
TacticImpact

“…causing damage to remote terminal units (RTUs)… and corrupted system firmware on OT devices.”

T1561Disk WipeEvidence3
TacticImpact

After a few hours, the hackers accessed another server that delivered software updates to the modems – which allowed them to deliver the wiper malware that researchers publicly identified last year. The attack took 40,000 to 45,000 modems offline, thousands of which never resumed operation.

T1561.001Disk Content WipeEvidence2
TacticImpact

Russian hackers targeted Ukrainian government websites in January, ahead of the invasion, installing “wiper” malware that permanently clears data from computer networks.

T1565Data ManipulationEvidence1
TacticImpact

It doesn’t just steal data; it erases it completely. We have seen instances where private institutions were targeted by such complex, AI-driven wiper attacks that managed to reach even their backup servers.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping11

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.