Cybercrime DB

Wiper Malware Campaigns Tied to Nation-State Actors

Destructive wiper malware has become a nation-state standard for sabotage and deniability.

Correspondent · · 11 min read
Cover illustration for “Wiper Malware Campaigns Tied to Nation-State Actors”
malware operators and developers · August 22, 2026 · 11 min read · 2,510 words

Wiper malware doesn't hold your data hostage. It kills it, permanently, and moves on to the next target. That's the whole story here: how a niche sabotage tool turned into standard nation-state kit, and why network defenders need to treat it as its own distinct threat category.

Here's the mechanism, stripped down. A wiper overwrites data with null or random bytes, or it "encrypts" the way ransomware does but throws away the key, or it goes straight for the Master Boot Record and Master File Table and corrupts them until the machine won't boot. Sometimes it dresses up as ransomware, complete with a ransom note and a countdown timer. The decryption path is gone before any payment is made, because destruction is the business model, if you can call something with no invoice a business at all.

That's also how you spot who's behind it. Criminal ransomware crews want money, so they need recovery to actually work. Wipers serve people who prioritise deniability over profit, which points at nation-states and the hacktivist personas they hide behind when they want deniability. Erase the evidence, deny the target its systems, send a message nobody can trace back cleanly.

Why nation-states reach for wipers rather than other cyber weapons

Four jobs, really: sabotage infrastructure, destroy evidence before anyone can look at it, send a loud and deniable message, and support a military operation by cutting off command and control right when it matters.

Take that last one. An hour before Russian troops crossed into Ukraine in February 2022, a wiper called AcidRain hit Viasat's KA-SAT satellite network, and Ukrainian military communications went dark at the exact moment they were needed most. This was scheduled, timed to the hour, built into a war plan the same way you'd schedule an artillery barrage.

Deniability does the rest of the work. Run the operation under a hacktivist name, borrow some code from a rival state's toolkit, and you get both things at once: the propaganda win of visible destruction, plus enough cover to shrug when someone points a finger. The math favors the attacker too, since building a wiper and getting it onto a network costs a sliver of what the resulting damage runs, and once it spreads across a few connected supply chains, that gap only grows.

It's worth separating wipers from spy tools early. Espionage malware stays hidden and collects data quietly for months or years, while a wiper leaves nothing standing and nothing recoverable.

Shamoon's 2012 strike on Saudi Aramco and what it established

August 15, 2012. A group calling itself Cutting Sword of Justice, linked to Iran, deployed something called Shamoon against Saudi Aramco. When the dust settled, more than 30,000 computers were wiped clean, roughly 85% of the company's Microsoft-based systems. Files, emails, documents, all replaced with an image of a burning American flag. That detail matters, because this was staged humiliation, built to be seen by as many people as possible.

The ripple effects were real. Oil markets moved, and hard-drive and memory prices spiked worldwide because Saudi Aramco needed replacement hardware fast and at scale. Recovery took months. An NSA document later called this the first destructive cyberattack the agency had seen coming out of Iran, which is a fairly remarkable sentence to have on the record anywhere. Shamoon 2.0 and 3.0 followed in 2016 and 2018, each sharper than the last: spearphishing for the initial break-in, and a driver called Eldos RawDisk that let the malware skip past Windows APIs entirely and write straight to the Master Boot Record.

Shamoon set the template everybody since has followed. A state actor with a grievance, a hacktivist mask, and destruction calibrated for both operational damage and public spectacle. Researchers still use it as the year-zero reference point for the whole category.

Table: Major Wiper Campaigns at a Glance. Compares Attributed Actor, Primary Target, Destruction Method, Cover Used, and 1 more by Shamoon (2012), NotPetya (2017), Olympic Destroyer (2018), HermeticWiper (2022), and 1 more.

NotPetya's global spread and the $10 billion lesson about collateral damage

NotPetya cost more than $10 billion, making it, at the time, the most expensive cyberattack ever recorded. In February 2018 the US, UK, and a coalition of allied governments formally pinned it on Russian GRU Unit 74455, the group known as Sandworm, in what was at the time the most coordinated joint statement of its kind.

Ukraine took the brunt of it, something like 80% of all infections. Government agencies, banks, energy providers, transit systems, all hit at once, and even the radiation monitoring system at Chernobyl went offline for a stretch. NotPetya spread through Ukrainian networks and then moved through global corporate networks fast, the way water finds every crack in a pipe. Maersk had to reinstall roughly 45,000 PCs and 4,000 servers, at a cost Maersk estimated between $200 and $300 million. FedEx's TNT division lost over $300 million, Merck lost $870 million, and Mondelez lost over $100 million. None of these companies were the actual target; they just happened to sit on the same network as one.

It looked like ransomware, right down to the ransom note demanding payment, but the encryption routine discarded the information needed to decrypt anything, so paying up would have gotten victims nothing at all. The legal fallout ran for years. Merck sued its insurer, Ace American, over a war-exclusion clause, and the 2022 ruling put pressure on how war-exclusion clauses in cyber-insurance policies get written. Merck eventually settled for $1.4 billion. NotPetya drove home a lesson Shamoon never had to teach: a wiper aimed at one country can send bills to companies an ocean away that never asked to be involved.

False flags and the PyeongChang operation as a turning point in attribution

Olympic Destroyer hit the 2018 Winter Olympics in PyeongChang and did exactly what it says on the label. Ticketing systems, internet access, Wi-Fi, broadcast feeds, all knocked out, with the malware deleting shadow copies behind it so recovery wasn't even on the table. Investigators moved fast, and the early forensic signals pointed hard at North Korea's Lazarus Group.

They were wrong. They were wrong on purpose, because whoever built Olympic Destroyer had planted code artefacts specifically to steer the investigation toward North Korea. The real culprit, later attribution work concluded, was Sandworm. Picture a burglar leaving somebody else's gloves at the scene; that's active misdirection built into the crime itself.

False flags matter for exactly this reason: they turn attribution into a weapon of its own. Every hour investigators spend chasing the wrong lead is an hour the real actor gets for cleanup, and a wrong public accusation can fracture alliance coordination or provoke retaliation against the wrong party entirely. North Korea's Lazarus Group had already set a precedent for this back in 2014, deploying a wiper component against Sony Pictures, the first US company ever hit by malware built to destroy rather than steal. Defenders now have to treat hacktivist personas, borrowed code, and stylistic mimicry as standard building blocks in these campaigns.

How the 2022 Ukraine invasion turned wiper malware into a volume weapon

Diagram: Wiper Malware: From Niche Tool to Volume Weapon (2012–2025). Visualizes: Show the escalation of wiper malware as a timeline of landmark incidents from 2012 to 2025, using the following anchors: 2012 Shamoon destroys 30,000 Saudi Aramco…

Something changed in scale once Russia invaded Ukraine. In the roughly two years before the invasion, researchers tracked a single wiper incident. In the twelve months around the invasion itself, that number jumped to 16 distinct wiper families, and Fortinet clocked a 53% jump in wiper activity between the third and fourth quarters of 2022 alone.

WhisperGate arrived in January 2022, weeks ahead of the invasion, quietly destroying data across Ukrainian organizations. This was preparation, staged well before the shooting started. Then came February 24, invasion day itself: HermeticWiper hit hours before troops crossed the border, hitting government agencies and critical services while slipping past Windows security features to reach low-level disk structures directly. CaddyWiper and IsaacWiper showed up that same day too, widening the blast radius across Windows domains and every attached drive they could reach.

AcidRain remains the sharpest example of precision in the whole campaign, the Viasat attack mentioned earlier that cut Ukrainian military communications an hour before the invasion started. The fallout traveled further than anyone in Moscow probably planned for. 5,800 Enercon wind turbines in Germany malfunctioned as a downstream effect, meaning a NATO member's energy infrastructure took collateral damage from an attack meant for Ukraine. Sixteen strains, deployed together or in close sequence, signals a planning cell with wiper malware pre-positioned like ammunition on a shelf, ready to pull the moment the timeline called for it.

Sandworm's decade of wiper operations and the NATO escalation in 2025

Sandworm didn't start in 2022, and it hasn't stopped since. Go back to 2015 and you'll find the group behind the first known malware-induced power blackout, an attack on Ukraine's power grid that left 230,000 people without electricity. From there the résumé runs through NotPetya, Olympic Destroyer, and the 2022 wiper surge. The disturbing part isn't any single incident; it's the consistency.

The pace never really slowed. SwiftSlicer showed up in 2023, and ZEROLOT followed in 2024 and into 2025. Both hit Ukrainian targets, and both suggest a group that treats wiper development as ongoing R&D with active long-term investment. AcidPour, which surfaced in 2024, is a technical evolution of AcidRain: bigger architecture, plus new ability to wipe RAID arrays and UBI file systems. The researcher who dug into it noted it could be harder to prevent and recover from than its predecessor, which is not a comforting sentence to read about malware that already knocked out a satellite network.

Then, in December 2025, Sandworm crossed a line it hadn't crossed before. EclecticIQ reported the group deployed something called DynoWiper against Poland's energy infrastructure, the first confirmed case of Sandworm's destructive capability hitting a NATO member's critical infrastructure directly. A Sandworm-adjacent group called ELECTRUM, which built ACIDPOUR and leans on its own hacktivist personas, shows this isn't one team working alone. It's an ecosystem inside Russia's GRU where persona-building and malware development run on parallel tracks. The trend line isn't subtle: Sandworm moved from Ukraine-only sabotage to operations that reach straight into NATO territory.

Iran's wiper ecosystem and the MDM pivot that bypasses endpoint detection

Iran takes a distinct approach. For the IRGC and the Ministry of Intelligence, wiper operations are cheap retaliation: enough damage to send a message, without the risk of starting a shooting war over it. Saudi, Israeli, and Albanian targets have all taken hits across a string of campaigns going back years.

The tooling has grown up too. Early Iranian wipers stuck to Windows. By 2024, families like Hamsa and BiBi were running on Linux, while a wiper called Hatef stuck to Windows, meaning Linux servers running critical infrastructure now sit squarely inside the target zone. Researchers flagged three new Iranian-linked families in a single month: BlueWipe and SewerGoo aimed at Israeli critical infrastructure and government networks, and BeepFreeze aimed at Albanian networks.

The most interesting technical shift, though, has nothing to do with malware at all. In one Iran-linked operation, attackers wiped hundreds of thousands of devices at a multibillion-dollar medical device manufacturer using Microsoft's own mobile device management platform. The attack ran entirely through legitimate cloud tooling, leaving no artefact an antivirus scanner would examine. The entire operation shows up only in Entra ID sign-in logs, Intune audit logs, and Azure AD activity logs, because the "weapon" here was the company's own legitimate management tool, turned against itself. Anyone whose detection strategy starts and ends with endpoint monitoring has a real problem here, since the activity occurs entirely outside endpoint visibility. Groups like Void Manticore and Handala Hack Team now run their operations openly on Telegram, mixing wiper attacks with psychological messaging campaigns. Iran basically took Russia's persona playbook and made it standard procedure.

PathWiper and what the 2025 Ukraine campaigns reveal about current technique

A new wiper in mid-2025, called PathWiper, was identified targeting a Ukrainian critical infrastructure organization. The findings drew attention when they landed. Nothing about this strain had shown up before.

That phrase, "previously unseen," is the part worth sitting with. Three years into sustained wiper campaigns against Ukraine, attackers continue building new families, which points to active development pipelines running in the background and a deliberate effort to dodge signature-based detection that would otherwise catch a known strain on sight. SwiftSlicer, ZEROLOT, PathWiper: three names spread across 2023 to 2025, and the pace between them hasn't let up. This is a standing layer of the conflict, sustained well beyond the opening weeks of the invasion.

Recent strains share some technical DNA, too. They go after OT-adjacent environments tied to critical infrastructure, firmware, low-level disk structures, and network-attached devices, not just the Windows workstation sitting on someone's desk. In a critical infrastructure setting, the absence of any recovery path carries more weight than in a typical corporate ransomware case, where operators can at least negotiate for a decryption key. A wiper hitting a power grid, a satellite network, or a water system leaves operators rebuilding from bare metal, often under wartime pressure with no room for a slow, careful restoration process.

How defenders can recognise wiper campaigns for what they are

Venn diagram: Wipers vs Ransomware: Purpose & Behavior. Compares Wiper Malware and Ransomware; overlap: Shared Traits.

Recovery feasibility is the right first question. Wipers show up disguised as ransomware, wrapped in hacktivist branding, or riding on legitimate management tools nobody thought to watch closely. Before anyone asks who did this, ask whether recovery is even structurally possible; if it isn't, the ransom note's claims are irrelevant, because the incident is destructive in nature.

Some patterns repeat often enough to be useful. Spearphishing shows up as an entry point again and again, in Shamoon 2.0 and in multiple Ukraine-linked strains. Supply-chain compromise put NotPetya on thousands of machines through a single accounting software update, and cloud identity abuse powered the MDM wipe at that medical device company. The delivery method changes case to case, but the intelligence footprint leading up to detonation tends to look similar across all of them. Timing is its own signal, too: pre-invasion hours, an Olympic opening ceremony, a diplomatic flashpoint — destructive activity clustering around a geopolitical event should trigger immediate escalation, not a routine ticket sitting in a queue.

The MDM case exposes a real gap. Any organization leaning entirely on endpoint detection has zero visibility into a wipe carried out through legitimate cloud tooling. Audit logs across identity platforms, device management systems, and cloud infrastructure need a seat inside the detection stack from the outset. Platform coverage matters too, since Linux servers, routers, modems, and satellite terminals are all confirmed wiper targets today, and a detection program built only around Windows endpoints leaves a growing chunk of the real attack surface exposed.

Speed is the clearest early warning you'll get. If a process is overwriting disk at volume, corrupting the Master Boot Record, or issuing bulk wipe commands through an MDM console, the window to contain it is measured in minutes, far shorter than a typical malware triage process assumes. Response playbooks need to treat suspected wiper activity the way emergency responders treat a mass-casualty event: act first, sort the paperwork later. Dates and dollar figures make for a decent timeline, but the real job is figuring out which of these techniques shows up on your own doorstep next, and building for that before it does.

Sources

  1. ien.com
  2. picussecurity.com
  3. csoonline.com
  4. cyberranges.com

More in malware operators and developers