Hackers Use Lotus Wiper To Destroy Drives In Energy Sector Cyberattack
ID: dc6a1e7f-a255-578b-987f-fe37aacc86ab
STIX ID: report--dc6a1e7f-a255-578b-987f-fe37aacc86ab
Feed Name: Cyber Press
Threat Score
A newly documented destructive campaign dubbed "Lotus Wiper" targets Venezuela's energy and utilities sector; researchers found orchestration batch scripts and a wiper binary that, once triggered via a NETLOGON-hosted XML flag, disables accounts and systematically destroys system recovery artifacts and every sector of physical drives (clearing USN journals, removing restore points, zeroing sectors and deleting files), leaving systems irrecoverable.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
