Attack outcomes
Wiper malware
Also called: wiper
Wiper malware is destructive software built to erase or corrupt data and make systems unusable, with no way to get the data back by paying. It sometimes poses as ransomware, but no payment brings the data back. Wipers are usually aimed at disruption, and attackers can deploy them with stolen administrator credentials across many machines.
How it works
Attackers get privileged access, then push the wiper to as many devices as possible through admin tools or group policy. The malware overwrites files, disk partitions or the boot record so machines cannot start. Recovery depends on clean offline backups and rebuilt systems.
A real example
CISA and the FBI said that ahead of Russia's attack on Ukraine, threat actors deployed destructive malware, including WhisperGate and HermeticWiper, against organizations in Ukraine to destroy computer systems and render them inoperable.
Source: Update: Destructive Malware Targeting Organizations in Ukraine (AA22-057A) — Cybersecurity and Infrastructure Security Agency (CISA), 2022-02-26
How to stop it
Limit and monitor the admin accounts that can push software to many machines, require phishing-resistant MFA for them, and keep offline backups those accounts cannot delete.
Related terms
Threat actors that use it
- Lazarus Group
Profile with government sources
Sources
- Update: Destructive Malware Targeting Organizations in Ukraine (AA22-057A) — Cybersecurity and Infrastructure Security Agency (CISA), 2022-02-26
Last reviewed Oct 2, 2026