Wiper
MITRE ATT&CK: S0041 View on attack.mitre.org
- First seen
- 2013-03-20 00:00:00
- Malware type
- wiper
- Family
- Malware family
- Related IoCs
- 216 (216 malicious)
- Last IoC activity
- 2026-09-02 02:14:03
- Profile updated
- 2026-07-07 15:29:04
Targeted industries: financial-services media-and-entertainment
Targeted regions: country_code:kr
Context
Wiper is a family of destructive malware used in March 2013 during breaches of South Korean banks and media companies.
Recent IoC activity
216 malicious indicators in Maltiverse are attributed to Wiper (S0041). The 20 most recently updated:
Detection coverage
- 4 Sigma rules
Malware & tools used
- Software Deployment Tools (attack-pattern)
Used by threat actors
- HomeLand Justice (campaign)
- May 2023 Exfiltration & Wiper Activity (Truebot + FlawedGrace + MBR Killer) (campaign)
Reports & references
- secureworks.com — Wiper Malware Analysis Attacking Korean Financial Sector (report)
- MITRE ATT&CK — S0041 (report)