logo

Venezuela energy sector targeted by highly destructive Lotus wiper

ID: 2a24ddb3-753a-5366-bcbc-bbd25839c934

STIX ID: report--2a24ddb3-753a-5366-bcbc-bbd25839c934

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-04-22

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Kaspersky researchers identified a targeted destructive campaign (Lotus Wiper) against Venezuela's energy and utilities sector in 2025–2026: attackers used coordinated batch scripts (e.g., OhSyncNow.bat) to disable defenses, isolate systems, and prepare the environment, then deployed a wiper that removes recovery mechanisms, overwrites physical drives, deletes and corrupts files and logs, and leaves systems unrecoverable; the report provides IOCs, TTPs (use of diskpart, robocopy, fsutil, NETLOGON monitoring), and mitigation advice including auditing domain shares, monitoring token/credential abuse, and robust backup testing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.