Many headline-making cybersecurity news stories evolve around phishing attacks and ransomware attacks. But wiper malware, a newer threat vector, might be far worse than phishing and ransomware combined.
As the name suggests, wiper malware erases a victim's systems. Also called wiperware , it is a malicious payload designed to cause total destruction to all of the data and programs in an organization's infrastructure. Wiperware is often used in cyberwarfare and in attacks against government agencies, critical infrastructure and mission-critical business processes.
Unlike ransomware and phishing , which have some possibility for data recovery after an attack, wiperware causes total loss and destruction. Wiperware can be compared to a Category 5 hurricane, while phishing and ransomware can be compared to tornadoes. Because of its wrath and level of severity, wiper malware could drive a company out of business, in that its purpose is to destroy data.
Wiper malware dates to 2012, when Kaspersky researchers published information Wiper malware used against Iranian computer systems and Shamoon wiperware used against a Saudi oil and gas company.
At the time, wiperware wasn't used widely because it eliminates the profit motive for cyberattackers. The first major wiperware uptick was noticed by several incident response companies in 2022, after Russia invaded Ukraine.
In the years since, wiperware has been used in many high-profile breaches and cyberwarfare attacks. Well-known variants include NotPetya , Industroyer, HermeticWiper , HermeticWizard and HermeticRansom .
Wiperware can affect an organization in four distinct ways:
Organizations will notice the effects of Trojan Horses, worms, viruses, malware and others at some point, but wiperware is different. Once a business has been hit, it will be immediately obvious because nothing can be accessed on targeted devices, VMs or virtual desktops. By then, it is too late to do anything it.
Since a wiperware attack doesn't result in any real financial gain, the question remains: Why do cyberattackers use it? Following are some key reasons:
No business or individual is immune to becoming a victim of a wiperware attack. Therefore, prevention is key. Use the following strategies to mitigate wiperware attacks:
Ravi Das is a technical engineering writer for an IT services provider. He is also a cybersecurity consultant at his private practice, ML Tech, Inc., and has the Certified in Cybersecurity (CC) certification from ISC2.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
