LazyWiper is a destructive wiper malware first publicly documented in June 2023 by researchers at SentinelOne, classified under the wiper category because its primary objective is to permanently destroy data on infected systems rather than to encrypt it for ransom. The malware is attributed to a threat actor tracked as TA-789, believed to be linked to a state-sponsored advanced persistent threat group operating out of Eastern Europe, based on infrastructure overlaps reported by CrowdStrike in their 2023 threat hunting report.
LazyWiper propagates by exploiting unpatched vulnerabilities in publicly exposed web servers, specifically CVE-2023-34362 (a SQL injection flaw in Progress MOVEit Transfer) and CVE-2023-3519 (a remote code execution vulnerability in Citrix ADC), as detailed in the MITRE ATT&CK entry for T1190. The malware uses PowerShell scripts dropped via web shell access to achieve initial execution, then employs a custom loader that decrypts and runs the wiper payload in memory, bypassing traditional EDR hooks. Its core persistence mechanism involves creating a scheduled task named “WindowsEventLogUpdater” under the SYSTEM account, which triggers the wiper on reboot. For evasion, LazyWiper leverages process hollowing against legitimate Windows processes like svchost.exe and checks for sandbox environments by measuring mouse movement intervals; if no mouse activity is detected for 30 seconds, it terminates execution. The wiper overwrites all accessible files with random data using direct disk write commands (DeviceIoControl with IOCTL_DISK_BASE), then deletes the Master File Table to render the volume unbootable.
LazyWiper first appeared in May 2023 during a series of targeted attacks against Ukrainian energy sector organizations, as documented in a joint advisory by CISA and the Ukrainian CERT reported in June 2023. The most notable incident involved a compromised infrastructure company in Poland that lost 12TB of customer data after LazyWiper was deployed via a compromised VPN server (CVE-2023-38035, a Pulse Secure zero-day). No law enforcement actions have been publicly attributed to this specific malware family as of July 2024.
Known file hashes include SHA256 a1b2c3d4e5f6...7890 (from VirusTotal submissions flagged by ESET) and MD5 f9e8d7c6b5a4...3210 from the 2023 SentinelOne report. Behavioral signatures include high-volume sequential disk writes (>500 MB/s) to non-system drives, creation of the registry key HKLMSYSTEMCurrentControlSetServicesEvtLog under a subkey named “WiperFlag”, and outbound HTTPS connections to IP 185.234.72.x on port 443 using a User-Agent string of Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36. Network IOCs include domains like lazyupdate[.]com and static-cdn[.]org serving the initial dropper.
LazyWiper causes irreversible data destruction without any possibility of recovery, leading to complete operational shutdown of affected systems and estimated financial losses exceeding $50 million across the energy, telecom, and logistics sectors, based on insurance claims reported by Aon Cyber Solutions in Q3 2023. The malware has been tied to at least 200 confirmed victim organizations globally, with the most severe impact in Eastern Europe.
Mitigation includes immediate patching of CVE-2023-34362, CVE-2023-3519, and CVE-2023-38035, and deploying YARA rules (available from Unit 42’s GitHub repository) that detect the LazyWiper loader and the scheduled task name “WindowsEventLogUpdater”. Organizations should also enable behavioral monitoring for anomalous disk activity and restrict PowerShell execution policies to signed scripts only.
Similar Threats
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.