logo

Wiper malware explained: How it works and why it’s so devastating

ID: d4c78d48-f6b9-5ba0-98e7-4dbc84bb919e

STIX ID: report--d4c78d48-f6b9-5ba0-98e7-4dbc84bb919e

Feed Name: ThreatLocker Blog

Threat Score
78/100

Date Published: 2025-07-07

Date Updated: 2026-05-01

...
...

A newly identified wiper called PathWiper was deployed in Ukraine in June 2025 using legitimate endpoint administration tools to overwrite and corrupt validated volumes; the report contextualises PathWiper alongside historical destructive wipers (NotPetya, Shamoon, HermeticWiper, etc.), outlines common wiper techniques (data/MBR/GPT overwrites, network propagation, supply-chain vectors), and recommends prevention controls such as application allowlisting and ringfencing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.