Skip to content

Wiper Malware

Risk Level

Wiper malware is designed purely for destruction — overwriting, encrypting without key, or deleting data to render systems unrecoverable. Unlike ransomware, there is no decryption key, no ransom demand, and no recovery. Wipers are typically nation-state tools for sabotage.

MilestoneYearDetails
Shamoon2012Saudi Aramco; 30K+ workstations
DarkSeoul2013South Korea banks/media; MBR wipe
Destover2014Sony Pictures; wiper + data theft
NotPetya2017Wiper disguised as ransomware; $10B+
Olympic Destroyer2018PyeongChang Olympics; false flags
ZeroCleare2019Iranian oil; MBR + partition wipe
Dustman2019Bahrain BAPCO; similar to ZeroCleare
HermeticWiper2022Ukraine; pre-invasion
IsaacWiper2022Ukraine; follow-on
CaddyWiper2022Ukraine; chain of wipers
1. PRIVILEGE ESCALATION
└─ Admin/SYSTEM/root required for disk access
2. DISABLE RECOVERY
└─ Delete shadow copies (vssadmin delete shadows)
└─ Disable Windows Recovery Environment
└─ Delete backup catalogs
3. MASTER BOOT RECORD (MBR) WIPE
└─ Overwrite sector 0 (bootloader + partition table)
└─ System unbootable
4. PARTITION TABLE WIPE
└─ Overwrite GPT/MBR partition structures
└─ Data inaccessible without forensic tools
5. FILE SYSTEM WIPE
└─ MFT/FTK overwrite (NTFS)
└─ Inode table overwrite (ext4)
└─ Selective: target user files, databases
6. FIRMWARE WIPE (advanced)
└─ UEFI variable corruption
└─ Drive firmware corruption
WiperYearAttributionTargetImpact
Shamoon2012Iran (Cutting Sword)Saudi Aramco30K+ workstations
DarkSeoul2013North KoreaSK banks/media48K+ systems
Destover2014North KoreaSony PicturesData theft + wipe
NotPetya2017Russia (Sandworm)Ukraine → global$10B+ damage
Olympic Destroyer2018Russia (Sandworm)PyeongChangFalse flag
ZeroCleare2019Iran (APT34)Middle East oilMBR + partition
HermeticWiper2022Russia (Sandworm)UkrainePre-invasion
CaddyWiper2022RussiaUkraineChain of wipers
IndicatorDetection
vssadmin delete shadowsEvent ID 4719, command line
MBR/partition writesRaw disk write monitoring
Mass file deletionFile system audit (Event ID 4663)
Boot failureReboot loops, no OS found
Process: cipher.exe /wFree space wiping
  • Offline, immutable backups (3-2-1, air-gapped)
  • Protected MBR/GPT — Secure Boot, TPM measured boot
  • Disable vssadmin for non-admins
  • Monitor raw disk writes — EDR kernel callbacks
  • Immutable infrastructure — Rebuild, don’t recover
  • Network segmentation — Limit lateral spread
  • Incident response — Wiper-specific playbook
TechniqueIDDescription
Data DestructionT1485Overwrite/delete data
Inhibit System RecoveryT1490Delete shadows, disable recovery
Disk WipeT1561MBR, partition, file system
Firmware CorruptionT1495UEFI/BIOS corruption