Find notable cyber news and cases, enriched with sources, timelines, and signals.

Lotus data-wiping malware used against Venezuelan energy and utilities organizations

Malware Activity
First reported
Last updated
Happening score
H score 32
1 unique sources, 1 articles

Summary

Hide ▲

The Lotus data-wiping malware was used in targeted attacks against energy and utilities organizations in Venezuela, putting victims at risk of irreversible system destruction. It relies on OhSyncNow.bat and notesreg.bat to weaken defenses, disable accounts, and block normal operations before the final payload runs. The wiper then overwrites drives, clears recovery data, and leaves compromised systems unrecoverable. The activity was observed in the context of a broader late-2025 destructive sequence that escalated into full disk wiping.

Related Happenings

Lotus Wiper destructive campaign targeting Venezuela's energy and utilities sector

Campaign
H score35 First: 22.04.2026 13:55 Last: 22.04.2026 13:55 Sources 1

About this happening: The Lotus Wiper operation targeted Venezuela's energy and utilities sector in a destructive campaign spanning the end of 2025 and the start of 2026, indicating...

Lotus Wiper destructive activity against Venezuelan energy systems

Malware Activity
H score32 First: 22.04.2026 13:55 Last: 22.04.2026 13:55 Sources 1

About this happening: Researchers uncovered Lotus Wiper, a previously undocumented data wiper, in destructive attacks against Venezuela. The operation targeted the energy and utilitie...

Timeline

  1. 21.04.2026 21:38 2 articles · 2mo ago

    Kaspersky analyzes Lotus data-wiping malware against Venezuelan energy targets

    Technical Analysis Update

    Kaspersky analyzes Lotus, a previously undocumented data-wiping malware uploaded from a machine in Venezuela in mid-December and used in targeted attacks against Venezuelan energy and utilities organizations. The destructive payload is described as being preceded by batch scripts such as OhSyncNow.bat and notesreg.bat that weaken defenses and obstruct normal operations before diskpart, robocopy, and fsutil are used to overwrite drives, clear recovery data, and delete files until compromised systems become unrecoverable.

    Show sources