Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

Princess Charlene looks stylish in Elie Saab for Monaco F1 Grand Prix

7 biggest takeaways from the 2026 edition

A lifetime of gentle screen time for your child is on sale for just $45 until June 14th

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » Lotus Wiper Malware Destroys Venezuelan Energy Systems
Celebrities

Lotus Wiper Malware Destroys Venezuelan Energy Systems

By April 22, 2026No Comments4 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ravi LakshmananApril 22, 2026Malware/Critical Infrastructure

Cybersecurity researchers have discovered a previously undocumented data wiper used in attacks targeting Venezuela between late last year and early 2026.

According to Kaspersky Lab’s findings, this novel file wiper, called Lotus Wiper, was used in a destructive campaign targeting Venezuela’s energy and utilities sector.

“The two batch scripts are responsible for initiating the destructive phase of the attack and preparing the environment for executing the final wiper payload,” the Russian cybersecurity vendor said. “These scripts coordinate the initiation of operations across the network, weakening system defenses, and disrupting normal operations before acquiring, deobfuscating, and executing unknown wipers.”

Once the wiper is deployed, it erases the recovery mechanism, overwriting the contents of the physical drive and systematically deleting files across the affected volumes, effectively rendering the system inoperable.

This artifact does not incorporate any extortion or payment instructions, indicating that the aggressive wiper activity is not aimed at financial gain. Notably, Wiper was uploaded from a Venezuelan machine to a public platform in mid-December 2025, weeks before the US military action in the country in early January 2026. Sample compiled in late September 2025.

It is currently unclear whether these two events are related, but Kaspersky noted that the samples were uploaded “at a time when public reports of malware activity targeting the same sectors and regions are increasing,” suggesting that the wiper attacks were highly targeted in nature.

The attack chain begins with a batch script that triggers a multi-step sequence that drops a wiper payload. Specifically, it attempts to stop the Windows Interactive Services Detection (UI0Detect) service. This service is used to alert the user when a background service running in session 0 attempts to display a graphical interface or interactive dialog.

UI0Detect has been removed from recent versions of Windows. The presence of such a setting indicates that the batch script is designed to work on computers running versions of Windows 10 earlier than version 1803, which had this feature removed.

The script then checks the NETLOGON share to access the remote XML file, and then checks if a corresponding file with the same name exists in the previously defined local directory (‘C:\lotus’ or ‘%SystemDrive%\lotus’). Proceed to run the second batch script regardless of whether such a local file exists.

“Local checks are likely to try to determine whether a machine is part of an Active Directory domain,” Kaspersky said. “If the remote file is not found, the script will exit. If the NETLOGON share cannot be reached initially, the script will introduce a random delay of up to 20 minutes before retrying the remote check.”

The second batch script, if not already run, enumerates local user accounts, disables cached logins, logs off active sessions, deactivates network interfaces, and runs the “diskpart clean all” command to erase all identified logical drives on the system.

It also recursively mirrors folders to overwrite existing content, uses the robocopy command line utility to delete folders, calculates available free space, and utilizes fsutil to create files that fill entire drives, exhausting storage space and preventing recovery.

Once the compromised environment is ready for destructive activity, Lotus Wiper is launched to delete restore points, overwrite physical sectors with all zeros, clear the volume’s journal update sequence number (USN), and erase all system files on each mounted volume.

Organizations and government agencies are encouraged to monitor changes to NETLOGON shares, potential credential dumping or privilege escalation activity, and use of native Windows utilities such as fsutil, robocopy, and diskpart to perform destructive actions.

“Given that the files contained specific functionality targeting older versions of the Windows operating system, the attackers likely had knowledge of the environment and could have compromised the domain long before the attack occurred,” Kaspersky said.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleTexas A&M’s optical propulsion technology could cut travel time to Alpha Centauri to 20 years
Next Article AI is spitting out more potential drugs than ever before. The startup wants to figure out which ones are important.

Related Posts

Princess Charlene looks stylish in Elie Saab for Monaco F1 Grand Prix

June 8, 2026

Aubrey Plaza wears Chanel Coco Beach Maternity Black Tie at 2026 Tony’s

June 8, 2026

Pink and daughter Willow bring textured drama to the 2026 Tony Awards

June 7, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Princess Charlene looks stylish in Elie Saab for Monaco F1 Grand Prix

7 biggest takeaways from the 2026 edition

A lifetime of gentle screen time for your child is on sale for just $45 until June 14th

HelloFresh has released an exclusive discount code – get 10 free meals and a Zwilling Dragon Wok

Trending Posts

Princess Charlene looks stylish in Elie Saab for Monaco F1 Grand Prix

June 8, 2026

7 biggest takeaways from the 2026 edition

June 8, 2026

Bob Dylan performs ‘You Ain’t Goin’ Nowhere’ for the first time in 14 years

June 8, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.