logo

Lotus Wiper Attack Targets Venezuelan Energy Firms, Utilities

ID: be107573-102e-57b1-a774-92a7fea90360

STIX ID: report--be107573-102e-57b1-a774-92a7fea90360

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2026-04-29

Date Updated: 2026-04-29

Author: Robert Lemos

...
...

A Kaspersky Lab analysis details a late‑2025 destructive malware campaign against Venezuela's energy/utilities sector that used two coordinating batch scripts and living‑off‑the‑land techniques to stage and execute a previously unknown wiper named Lotus Wiper; the wiper removes recovery mechanisms, overwrites physical drives, and systematically deletes files, leaving systems unrecoverable. Timing of the samples aligns with reported disruption at PDVSA in December 2025; attribution is not provided. The report highlights the trend of nation‑state style wiper attacks against critical infrastructure and recommends segmentation, immutable backups, remote access security, and rapid detection/response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.