ZOVWiper is a destructive data-wiping malware identified by ESET researchers and attributed to the Sandworm threat group with high confidence. It was first observed in November 2025 during an attack on a financial institution and was later seen in an incident affecting the energy sector, indicating targeting of critical sectors including financial and energy organizations. The malware iterates over fixed drives on compromised Windows systems and overwrites file contents using size-based overwrite logic to destroy data irrecoverably. It skips key system directories during the wiping process, but is designed to render systems inoperable through large-scale data destruction. Researchers assessed its behavior as consistent with Sandworm destructive campaigns and noted technical parallels with DynoWiper, which reinforced the attribution. Supporting detection content also associates ZOVWiper with behaviors such as high-frequency file deletion, suspicious wallpaper modification, use of shutdown.exe for impact, and rmdir-based indicator removal, though the core high-confidence functionality directly described is destructive wiping of files across fixed drives.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ZOVWiper is a destructive data-wiping malware identified by ESET researchers, attributed to the threat group Sandworm with high confidence. First observed in November 2025 targeting a financial institution and later in an energy sector incident, ZOVWiper systematically iterates over fixed drives and overwrites file contents to destroy data irrecoverably.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Destructive malware/wiper referenced as associated with file deletion activity.
ZOVWiper is referenced as a named malware family in an associated analytic story. The content does not describe its functionality further.
A destructive wiper malware that traverses fixed drives, selectively overwrites file contents based on size, skips key system directories, and renders systems inoperable to irrecoverably destroy data.
Associated Analytic Story ZOVWiper
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.