216.73.217.22

Highly destructive Lotus Wiper used in a targeted attack

· Published 21/04/2026 12:09 · Modified 21/04/2026 15:28

Export JSON

Essential information

Published
21/04/2026 12:09
Modified
21/04/2026 15:28
Tags
2026-04-21 batch scripts critical-infrastructure destructive attack disk wiping energy sector lotus wiper targeted campaign venezuela
Related entities
19 techniques (mitre), 1 malware, 2 others

Description

A highly targeted destructive wiper campaign dubbed '' was discovered targeting the energy and utilities sector in during late 2025 and early 2026. The attack begins with coordinating execution across networks using domain shares as trigger mechanisms. These scripts disable security services, lock out users, and prepare the environment for the final payload. The systematically destroys data by wiping physical drives with zeros, deleting restore points, clearing USN journals, and recursively deleting files. Unlike ransomware, this wiper has no financial motivation or ransom demands, designed purely for data destruction. Evidence suggests attackers maintained long-term domain access prior to the attack, with the wiper compiled months before deployment. The malware targets older Windows systems and uses legitimate system tools like diskpart, robocopy, and fsutil.

External references