Lotus Wiper Hits Energy Sector in Destructive Cyberattack
ID: 610c0ef7-9292-521f-8bda-cac04a3fe06e
STIX ID: report--610c0ef7-9292-521f-8bda-cac04a3fe06e
Feed Name: GBHackers
Threat Score
Lotus Wiper is a destructive malware campaign observed against Venezuelan energy and utilities organizations that uses network-wide batch-script orchestration (OHSync.xml via NETLOGON) and living-off-the-land tools (diskpart, robocopy, fsutil), followed by a low-level wiper that removes restore points, clears USN journals, and overwrites physical drives, leaving systems unrecoverable; artifacts indicate months of prior access and strategic (non-financial) motivations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
