Critical severity Malware

Wiper Malware

Destroys data and often the boot record, with no recovery path and no ransom demand.

Overview

Wipers are built to cause operational damage rather than profit: they overwrite files, corrupt the MBR, or abuse legitimate disk-management drivers to wipe at volume level.\nSome are dressed up as ransomware to misdirect the investigation.\nThe only meaningful defence is tested, offline, immutable backups.

Indicators of Compromise

Signals that suggest this is present on a system.

  • Mass file overwrites with random content
  • Boot record replaced with a message
  • Legitimate disk drivers used by an unsigned process

Controls that stop it

  • Keep Tested, Offline Backups

    Backups are the difference between an incident and a catastrophe. Store copies offline or on immutable storage the production identity cannot modify, encrypt them, and restore-test on a schedule. A backup you have never restored is a hypothesis, not a recovery plan. This is the control that neutralises ransomware and wipers regardless of how the intrusion began.

We use only the cookies needed to run this site — your session, your sign-in state and CSRF protection. There are no advertising or analytics trackers. How cookies are used