ZeroCleare

Malware

⚠️ Overview

ZeroCleare is a destructive data-wiper malware first identified in December 2019 by Intezer and IBM X-Force. It is attributed to the Iranian state-sponsored threat group APT34 (also known as OilRig, HelixKitten). ZeroCleare is categorized as a wiper—not ransomware—because it irreversibly destroys data without providing any recovery mechanism.

🔧 Technical Capabilities

ZeroCleare targets Windows systems by exploiting Sysinternals PsExec for lateral movement and EternalBlue-like exploits to propagate across networks. It uses a legitimate Broadcom driver (EaseUS Partition Master drivers, specifically partmgr.sys) to gain direct disk access, then overwrites all Master Boot Records (MBR) and partitions with garbage data. The malware communicates over SMB and WMI for command execution, and it disables Volume Shadow Copy (VSS) to prevent recovery. Evasion techniques include obfuscated PowerShell scripts and living-off-the-land binaries.

📜 History & Notable Incidents

ZeroCleare was first observed in attacks against Middle Eastern energy and industrial organizations in late 2019. IBM X-Force reported that the campaign targeted at least a dozen companies in Saudi Arabia and Israel, leveraging compromised credentials to deploy the wiper via domain controllers. No CVEs are directly exploited by ZeroCleare itself, but it relies on known vulnerabilities such as CVE-2017-0143 (EternalBlue) for initial access. No law enforcement actions have been publicly linked to this malware family.

🔍 Detection Indicators

Known file hashes for ZeroCleare include e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (SHA-256 of a sample) per VirusTotal intelligence. Behavioral indicators include sudden deletion of Volume Shadow Copies via vssadmin.exe, execution of diskpart.exe with cleanup commands, and network connections to internal SMB shares on port 445. Registry keys created under HKLMSYSTEMCurrentControlSetServices for the malicious driver. No unique mutex names are publicly documented.

☠️ Risk & Impact

ZeroCleare causes complete and irreversible data destruction on all connected drives, leading to extended operational downtime and financial losses estimated in the millions per incident. The primary targets are industrial control systems (ICS) and energy sector organizations, particularly in the Middle East, where data loss can disrupt critical infrastructure. No data exfiltration is performed; the aim is pure destruction.

🛡️ Mitigation

Recommended defenses include applying MS17-010 patches to block EternalBlue, restricting PsExec and administrative tools via AppLocker or Windows Defender ASR rules, and implementing strict network segmentation to limit lateral movement. Microsoft Defender for Endpoint detects ZeroCleare behavior as Trojan:Win32/ZeroCleare. Regular offline backups and monitoring for unauthorized driver installations are critical.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.