Malware · 145 days ago
The real failure point is not the wiper itself. Lotus first strips away recovery and normal operations, so by the time the destructive payload runs, the environment has already lost the defenses that might have contained or reversed the damage.
Kaspersky says the previously undocumented Lotus wiper was used against energy and utilities organizations in Venezuela. The malware was uploaded from a machine in Venezuela in mid-December and uses batch scripts to disable services, cut network interfaces, deactivate cached logins, and then overwrite physical drives, leaving systems unrecoverable.
That sequence matters because it turns defense degradation into part of the attack. In critical infrastructure, the danger is not just data loss. It is the loss of the ability to restore operations after the wipe starts.
4 sources covering this story
The Record from Recorded Future
Hackers deployed wiper malware in destructive attacks on Venezuela’s energy sector
Hackers deployed a previously unknown wiper malware against Venezuela’s energy and utilities sector in an attack that appears to have been designed to destroy systems.
Lotus Wiper Malware Targets Venezuelan Energy Systems in Destructive Attack
Lotus Wiper hit Venezuela’s energy sector in late 2025, exploiting pre-Windows 10 1803 systems, wiping drives and crippling operations.
New Wiper Malware Targeted Venezuelan Energy Sector Prior to US Intervention
Dubbed Lotus Wiper, the malware targets recovery mechanisms, overwrites drives, and systematically deletes files.
New Lotus data wiper used against Venezuelan energy, utility firms
A previously undocumented data-wiping malware dubbed Lotus was used last year in targeted attacks against energy and utilities organizations in Venezuela.
Part of the PlainSec briefing for 2026-04-23