Lotus Wiper is a destructive Windows wiper used in a highly targeted campaign against the energy and utilities sector in Venezuela during late 2025 and early 2026. The malware is designed to render systems unrecoverable rather than extort victims. It removes recovery mechanisms, deletes Windows restore points, overwrites physical drives and disk sectors with zeroes, clears volume change-journal data, and systematically destroys files across mounted volumes by zeroing contents, renaming them, and deleting them. Locked files can be scheduled for deletion on reboot. The malware relies on pre-existing elevated rights and enables privileges in its current token to perform administrative actions.
The destructive phase was coordinated with batch scripts and native Windows utilities, indicating substantial pre-attack staging and familiarity with the victim environment. Associated scripts were used to trigger execution across domain-joined systems, disable or hinder defensive and recovery actions, enumerate and disable local accounts, change passwords, disable cached logons, force user logoff, disable network interfaces, wipe logical drives with built-in disk utilities, mirror directories to overwrite or remove content, and exhaust free disk space to complicate recovery. The final payload was staged behind masqueraded executable names resembling legitimate HCL Domino components and decrypted immediately before execution.
Operational characteristics suggest the attackers had prior access to the environment for months and tailored the attack for older Windows systems, including logic involving the deprecated UI0Detect service. No ransom demand or payment mechanism has been associated with Lotus Wiper, and public reporting has not established attribution to a specific threat actor. The campaign has been assessed as geopolitically motivated destructive activity aimed at critical infrastructure rather than financially motivated crime.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
The attack chain begins with a batch file called OhSyncNow.bat.
The wiper requires elevated privileges, often gained after attackers move from low-level accounts to higher access.
The malware masquerades as legitimate HCL Domino application components, with file names like nstats.exe, nevent.exe, and ndesign.exe designed to blend in with normal system activity.
"assiduously identified and deleted critical data" and "systematically deletes files across affected volumes"
and deletes files throughout a system’s storage, leaving affected machines impossible to restore.
The wiper requires elevated privileges, often gained after attackers move from low-level accounts to higher access.
Security teams should watch for token abuse, credential theft, and privilege escalation in logs.
The first argument refers to a file with XOR encryption applied to its entire contents; the decrypted contents are saved in the second file... the only purpose of nstats.exe is to decrypt and restore the wiper’s executable, which may have been encrypted to avoid detection.
"Lotus Wiper operators dwelled in the environment for months, staging binaries and preparing the terrain before executing the destructive phase."
The second batch script, if not run already, enumerates local user accounts...
"The wiper removes recovery mechanisms, overwrites the content of physical drives, and systematically deletes files across affected volumes, ultimately leaving the system in an unrecoverable state," the cybersecurity firm's researchers stated.
"The wiper removes recovery mechanisms, overwrites the content of physical drives, and systematically deletes files across affected volumes..."
It enumerates local user accounts, changes their passwords to random strings, marks them inactive, disables cached logins, logs off active sessions, and shuts down all network interfaces using netsh.
It enumerates local user accounts, changes their passwords to random strings, marks them inactive, disables cached logins, logs off active sessions
A Wiper Attack on a Venezuelan Oil Company: Reverse Engineering the Lotus Wiper that Disrupted PDVSA Systems
The second batch script... runs the "diskpart clean all" command to wipe all identified logical drives on the system. | Once the compromised environment is prepared for destructive activity, the Lotus Wiper is launched to delete restore points, overwrite physical sectors by writing all zeroes...
It also recursively mirrors folders to overwrite existing contents or delete them using the robocopy command-line utility, and calculates available free space and utilizes fsutil to create a file that fills the entire drive to exhaust storage capacity and impair recovery.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named wiper malware discussed as the tool used in an attack that disrupted PDVSA systems at a Venezuelan oil company.
A destructive wiper malware used against Venezuelan energy and utilities targets. It removes recovery mechanisms, overwrites physical drives, and systematically deletes files across affected volumes, leaving systems unrecoverable. The attack also relied heavily on living-off-the-land techniques and staged binaries over months before execution.
Destructive wiper malware used in a targeted, likely geopolitically motivated attack. It disables recovery mechanisms, deletes Windows System Restore points, overwrites physical drives and disk sectors with zeros, exhausts free space, zeroes and deletes files, and can schedule deletion of locked files on reboot. It masquerades as legitimate HCL Domino components and appears to be deployed after prior access is established.
A destructive data wiper used in targeted attacks against Venezuela's energy and utilities sector. It prepares systems for destruction via batch scripts, disables defenses and recovery mechanisms, wipes logical drives, overwrites physical sectors with zeroes, clears USN journals, deletes restore points, and systematically erases files across mounted volumes to render systems inoperable.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.