Wiper malware explained: How it works and why it’s so devastating
ID: d4c78d48-f6b9-5ba0-98e7-4dbc84bb919e
STIX ID: report--d4c78d48-f6b9-5ba0-98e7-4dbc84bb919e
Feed Name: ThreatLocker Blog
Threat Score
A newly identified wiper called PathWiper was deployed in Ukraine in June 2025 using legitimate endpoint administration tools to overwrite and corrupt validated volumes; the report contextualises PathWiper alongside historical destructive wipers (NotPetya, Shamoon, HermeticWiper, etc.), outlines common wiper techniques (data/MBR/GPT overwrites, network propagation, supply-chain vectors), and recommends prevention controls such as application allowlisting and ringfencing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
