Files

21 lines
1.8 KiB
YAML
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
name: Disk Wiper
id: 493a72ab-abd2-4787-a47b-589f817fd1ce
version: 2
creation_date: '2025-06-27'
modification_date: '2026-05-13'
author: Teoderick Contreras, Splunk
status: production
description: This malware sample is identified as a destructive disk wiper designed to irreversibly erase data on infected systems. Once executed, it overwrites or corrupts disk partitions, rendering files and operating systems unusable. Often deployed in targeted attacks or sabotage campaigns, it aims to cripple victims by destroying critical data rather than stealing it. Analysis on VirusTotal shows multiple detections labeling it as “Trojan.Wiper” or “DiskWiper,” indicating destructive intent and possible use of raw disk access to bypass file-level recovery. Such tools are frequently employed in cyber warfare, ransomware incidents (as fake “wipers”), or hacktivist attacks to maximize damage and disruption.
narrative: When this wiper malware lands on a system, it doesnt bother with stealth or theft—its here to destroy. Once launched, it hunts for disks and partitions to corrupt, overwriting data in a deliberate act of sabotage. Victims see their machines reduced to useless bricks, with operating systems unbootable and files lost forever. Security analysts on VirusTotal tag it plainly a wiper, engineered to inflict maximum damage. Its the kind of tool favored in cyberwarfare and hacktivist attacks, leaving no ransom note—just devastation. For its operators, data isnt treasure to steal; its fuel to burn in a campaign of pure destruction.
references:
- https://x.com/cyb3rops/status/1935707307805134975
category:
- Data Destruction
- Malware
- Adversary Tactics
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
usecase: Advanced Threat Detection