Wiper is a family of destructive malware used in March 2013 during breaches of South Korean banks and media companies. (Citation: Dell Wiper)
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
temporary Windows files generated by Wiper begin with a tilde character (~), followed by the letter d (either capital or lower case), followed by other letters or numbers. This “tilded platform,” as researchers have come to call the convention, is also found in both Stuxnet and Duqu.
Several attacks shared similar methods in that they specifically overwrote the master boot record (MBR) of computers hard drives, which then needed to be physically replaced in many cases.
Several attacks shared similar methods in that they specifically overwrote the master boot record (MBR) of computers hard drives... Similar methods were used in March 2013 to wipe the hard drives of major South Korean banks and media outlets, as well as in the cyber attack against Sony in November 2014.
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A destructive wiper malware sample themed around the Tokyo Olympics. It performs anti-VM, anti-debugging, and anti-sandbox checks, then deletes files under the user's profile matching predefined extensions such as .doc, .docx, .pdf, .csv, .xls, .xlsx, .ppt, .pptx, .txt, .log, .exe, and Japanese word processor formats like .jtd/.jtt. If analysis tools are detected, it exits and deletes itself; after execution it self-destructs.
Earlier destructive malware referenced for comparison; the article explicitly says the analyzed malware is not the original Wiper and notes differences in service names, driver filenames, and disk wiping pattern.
A highly destructive malware that permanently purges large portions of hard drives from infected computers. It reportedly attacked Iran’s oil ministry and shared a file-naming convention similar to Stuxnet and Duqu.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.