logo

Lotus Wiper Hits Energy Sector in Destructive Cyberattack

ID: 610c0ef7-9292-521f-8bda-cac04a3fe06e

STIX ID: report--610c0ef7-9292-521f-8bda-cac04a3fe06e

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-04-22

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Lotus Wiper is a destructive malware campaign observed against Venezuelan energy and utilities organizations that uses network-wide batch-script orchestration (OHSync.xml via NETLOGON) and living-off-the-land tools (diskpart, robocopy, fsutil), followed by a low-level wiper that removes restore points, clears USN journals, and overwrites physical drives, leaving systems unrecoverable; artifacts indicate months of prior access and strategic (non-financial) motivations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.