Wiper malware is designed purely for destruction — overwriting, encrypting without key, or deleting data to render systems unrecoverable. Unlike ransomware, there is no decryption key , no ransom demand , and no recovery . Wipers are typically nation-state tools for sabotage.
Milestone Year Details Shamoon 2012 Saudi Aramco; 30K+ workstations DarkSeoul 2013 South Korea banks/media; MBR wipe Destover 2014 Sony Pictures; wiper + data theft NotPetya 2017 Wiper disguised as ransomware; $10B+ Olympic Destroyer 2018 PyeongChang Olympics; false flags ZeroCleare 2019 Iranian oil; MBR + partition wipe Dustman 2019 Bahrain BAPCO; similar to ZeroCleare HermeticWiper 2022 Ukraine; pre-invasion IsaacWiper 2022 Ukraine; follow-on CaddyWiper 2022 Ukraine; chain of wipers
└─ Admin/SYSTEM/root required for disk access
└─ Delete shadow copies (vssadmin delete shadows)
└─ Disable Windows Recovery Environment
└─ Delete backup catalogs
3. MASTER BOOT RECORD (MBR) WIPE
└─ Overwrite sector 0 (bootloader + partition table)
└─ Overwrite GPT/MBR partition structures
└─ Data inaccessible without forensic tools
└─ MFT/FTK overwrite (NTFS)
└─ Inode table overwrite (ext4)
└─ Selective: target user files, databases
6. FIRMWARE WIPE (advanced)
└─ UEFI variable corruption
└─ Drive firmware corruption
Wiper Year Attribution Target Impact Shamoon 2012 Iran (Cutting Sword) Saudi Aramco 30K+ workstations DarkSeoul 2013 North Korea SK banks/media 48K+ systems Destover 2014 North Korea Sony Pictures Data theft + wipe NotPetya 2017 Russia (Sandworm) Ukraine → global $10B+ damage Olympic Destroyer 2018 Russia (Sandworm) PyeongChang False flag ZeroCleare 2019 Iran (APT34) Middle East oil MBR + partition HermeticWiper 2022 Russia (Sandworm) Ukraine Pre-invasion CaddyWiper 2022 Russia Ukraine Chain of wipers
Indicator Detection vssadmin delete shadowsEvent ID 4719, command line MBR/partition writes Raw disk write monitoring Mass file deletion File system audit (Event ID 4663) Boot failure Reboot loops, no OS found Process: cipher.exe /w Free space wiping
✅ Offline, immutable backups (3-2-1, air-gapped)
✅ Protected MBR/GPT — Secure Boot, TPM measured boot
✅ Disable vssadmin for non-admins
✅ Monitor raw disk writes — EDR kernel callbacks
✅ Immutable infrastructure — Rebuild, don’t recover
✅ Network segmentation — Limit lateral spread
✅ Incident response — Wiper-specific playbook
Technique ID Description Data Destruction T1485 Overwrite/delete data Inhibit System Recovery T1490 Delete shadows, disable recovery Disk Wipe T1561 MBR, partition, file system Firmware Corruption T1495 UEFI/BIOS corruption