New Lotus data wiper used against Venezuelan energy, utility firms
ID: d5fa4445-4a31-5130-94ae-3a43b99b3e9a
STIX ID: report--d5fa4445-4a31-5130-94ae-3a43b99b3e9a
Feed Name: Bleeping Computer
Kaspersky analyzed a previously undocumented data-wiping malware called Lotus used in targeted attacks against Venezuelan energy and utility organizations; attackers used preparatory batch scripts to disable defenses and accounts, then deployed a low-level wiper that clears USN journals, deletes restore points, overwrites physical disk sectors, and zeroes files to render systems unrecoverable. The report highlights precursor TTPs (UI0Detect manipulation, NETLOGON share changes, mass account modifications, and unusual use of diskpart/robocopy/fsutil) and recommends monitoring these indicators and maintaining validated offline backups.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
