Meteor
MITRE ATT&CK: S0688 View on attack.mitre.org
Aliases: Meteor
- Malware type
- wiper
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 1 (1 malicious)
- Last IoC activity
- 2026-08-27 16:16:25
- Profile updated
- 2026-07-07 13:01:30
Targeted industries: government-and-public-sector transportation-and-logistics
Targeted regions: country_code:ir
Context
Meteor is a wiper that was used against Iranian government organizations, including Iranian Railways, the Ministry of Roads, and Urban Development systems, in July 2021. Meteor is likely a newer version of similar wipers called Stardust and Comet that were reportedly used by a group called "Indra" since at least 2019 against private companies in Syria.
Recent IoC activity
1 malicious indicator in Maltiverse are attributed to Meteor (S0688). The 1 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | 2aa6e42cb33ec3c132ffce425a92dfdb5e29d8ac112631aec068c8a78314d49b.zip | 2026-08-27 | 1 |
Detection coverage
- 672 Sigma rules
Malware & tools used
- Service Stop (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Masquerade Task or Service (attack-pattern)
- Clear Windows Event Logs (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- Native API (attack-pattern)
- Internal Defacement (attack-pattern)
- Scheduled Task (attack-pattern)
- PowerShell (attack-pattern)
- Account Access Removal (attack-pattern)
- System Information Discovery (attack-pattern)
- Hidden Window (attack-pattern)
- Windows Command Shell (attack-pattern)
- Inhibit System Recovery (attack-pattern)
- Data Destruction (attack-pattern)
- Security Software Discovery (attack-pattern)
- File Deletion (attack-pattern)
- Process Discovery (attack-pattern)
- Group Policy Modification (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
Reports & references
- twitter.com — 1541753913732366338 (report)
- research.checkpoint.com — Indra Hackers Behind Recent Attacks On Iran (report)
- CrowdStrike — The Anatomy Of Wiper Malware Part 1 (report)
- CrowdStrike — The Anatomy Of Wiper Malware Part 3 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Meteor (report)
- threatpost.com — 168262 (report)
- labs.sentinelone.com — Meteorexpress Mysterious Wiper Paralyzes Iranian Trains With Epic Troll (report)
- MITRE ATT&CK — S0688 (report)