Skip to main content

Threats Tagged 'wiper'

View all threats tagged with 'wiper'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: wiper

Threats Tagged 'wiper'

Click on any threat for detailed analysis and mitigation recommendations

Check Point Research discovered critical flaws in VECT 2.0 ransomware affecting Windows, Linux, and ESXi platforms. A fundamental encryption implementation error causes files larger than 128 KB to be permanently destroyed rather than encrypted. The malware uses ChaCha20-IETF cipher but only saves one of four decryption nonces required for large files, making recovery impossible even after ransom payment. VECT's encryption speed modes are non-functional, thread scheduling degrades performance, and anti-analysis code is unreachable. Despite partnerships with TeamPCP and BreachForums for distribution, the technical implementation demonstrates amateur execution behind a professional facade. The nonce-handling flaw exists across all platform variants since initial deployment, effectively transforming this ransomware into a wiper for enterprise assets including VM disks, databases, and backups.

Join the discussion

A new payload in the TeamPCP arsenal has been discovered, capable of wiping entire Kubernetes clusters. The script uses the same ICP canister as the CanisterWorm campaign, with consistent lateral movement via DaemonSets. However, this variant introduces a geopolitically targeted destructive payload aimed specifically at Iranian systems. The malware checks timezone and locale to identify Iranian systems, deploying privileged DaemonSets across every node in Kubernetes environments. Iranian nodes are wiped and force-rebooted, while non-Iranian nodes receive the CanisterWorm backdoor. The latest variant adds network-based lateral movement, exploiting exposed Docker APIs and using SSH for spread. This development shows TeamPCP's ability to operate at supply chain scale and their willingness to engage in destructive actions.

Join the discussion

In late 2025, Poland's energy system was targeted by a major cyberattack, now attributed to the Russia-aligned APT group Sandworm by ESET Research. The attack involved data-wiping malware named DynoWiper, detected as Win32/KillFiles.NMO. While the full impact is still under investigation, researchers noted the attack's timing coincided with the 10th anniversary of Sandworm's 2015 attack on Ukraine's power grid. Sandworm continues to target critical infrastructure, particularly in Ukraine, with regular wiper attacks. The group's history of disruptive cyberattacks and the similarities in tactics, techniques, and procedures led to a medium-confidence attribution of this latest incident to Sandworm.

Join the discussion

A comprehensive analysis of a Potentially Unwanted Application (PUA) identified as HEURRemoteAdmin.GoToResolve.gen reveals its association with the GoTo Resolve Unattended Access application. While digitally signed by GoTo Technologies USA, LLC, the sample exhibits behaviors typical of PUAs, including silent installation, background thread execution, and persistent presence on the system. The application's use of the Restart Manager library, often seen in ransomware and wiper malware, raises concerns. Although no direct malicious payload was observed, the remote access capabilities present a significant security risk, potentially allowing unauthorized system control or deployment of secondary malware. The sample's detection by UltraAV further supports its classification as a security threat, warranting removal unless explicitly authorized and managed within organizational security policies.

Join the discussion

On February 24, 2022, a cyberattack exploited a VPN vulnerability in Viasat's KA-SAT satellite network, deploying AcidRain wiper malware. This attack disrupted satellite communications for thousands of users in Ukraine and disabled 5,800 wind turbines in Germany. The malware shares similarities with the VPNFilter malware family and targeted management systems to cause widespread operational disruption. Although impactful, the attack was less severe than other infrastructure attacks on Ukraine during the same period. The incident underscores the vulnerabilities in satellite network security and the critical need for robust defenses against sophisticated cyber threats targeting critical infrastructure. No known exploits are currently active in the wild, and the attack required access through a VPN vulnerability. European organizations relying on satellite communications and renewable energy infrastructure are particularly at risk. Mitigation requires patching VPN vulnerabilities, enhancing network segmentation, and monitoring for indicators of compromise related to AcidRain. Germany is notably affected due to the impact on its wind turbines, and other European countries with similar infrastructure and satellite dependencies should remain vigilant.

Join the discussion

A destructive attack on Ukrainian critical infrastructure using a new wiper malware called 'PathWiper' has been observed. The attack, attributed to a Russia-nexus APT group, utilized a legitimate endpoint administration framework to deploy the wiper across connected endpoints. PathWiper overwrites file system artifacts with random data, targeting physical drives, volumes, and network shared drives. Its capabilities are similar to HermeticWiper, previously used against Ukrainian entities. The malware's sophisticated approach to identifying and corrupting connected drives and volumes distinguishes it from earlier wipers. This attack underscores the ongoing threat to Ukrainian infrastructure despite the prolonged conflict with Russia.

Join the discussion

Showing 1 to 6 of 6 results

Filters:Tag: wiper
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses