Wiper Attack Removes Recovery Before Destruction Begins

The real failure point is not the wiper itself. Lotus first strips away recovery and normal operations, so by the time the destructive payload runs, the environment has already lost the defenses that might have contained or reversed the damage. Kaspersky says the previously undocumented Lotus wiper was used against energy and utilities organizations in Venezuela. The malware was uploaded from a machine in Venezuela in mid-December and uses batch scripts to disable services, cut network interfaces, deactivate cached logins, and then overwrite physical drives, leaving systems unrecoverable. That sequence matters because it turns defense degradation into part of the attack. In critical infrastructure, the danger is not just data loss. It is the loss of the ability to restore operations after the wipe starts.

Part of the PlainSec briefing for 2026-04-23

Sources