Hackers Use Lotus Wiper to Destroy Drives and Delete Files in Energy Sector Attack
ID: 9c90603d-a342-546f-a147-181be726a2db
STIX ID: report--9c90603d-a342-546f-a147-181be726a2db
Feed Name: cybersecurityNews.com
Lotus Wiper is a newly identified destructive wiper used in a targeted, geopolitically motivated attack against Venezuela's energy and utilities sector; the malware and supporting batch scripts (OhSyncNow.bat, notesreg.bat) use a NETLOGON-based trigger, credential/tokens manipulation, and native Windows utilities and low-level IOCTL calls to zero-drive, clear recovery mechanisms, and render systems unrecoverable. Artifacts indicate compilation in September 2025 and deployment activity in December 2025, and the report includes filenames, behavior details, and operational mitigations such as auditing NETLOGON, monitoring native tool usage, and hardening backup and restore processes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
