logo

Lotus Wiper Malware Targets Venezuelan Energy Systems in Destructive Attack

ID: 92462cf3-02ab-510d-80ed-0f03c01c5129

STIX ID: report--92462cf3-02ab-510d-80ed-0f03c01c5129

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-04-22

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Kaspersky researchers identified "Lotus Wiper," a previously unknown destructive file wiper used in late 2025–early 2026 attacks targeting Venezuela's energy and utilities sector; the campaign leverages two batch scripts to coordinate network-wide destructive actions (stopping legacy services, checking NETLOGON shares, disabling logins, deactivating interfaces) and then uses native Windows tools (diskpart, robocopy, fsutil) and a wiper payload to overwrite physical sectors, delete files and restore points, and render systems inoperable—organizations should monitor NETLOGON activity, credential/privilege escalation signs, and misuse of native utilities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.