Meteor

MITRE ATT&CK: S0688 View on attack.mitre.org

Aliases: Meteor

Malware type
wiper
Family
Malware family
Operating systems
windows
Related IoCs
1 (1 malicious)
Last IoC activity
2026-08-27 16:16:25
Profile updated
2026-07-07 13:01:30

Targeted industries: government-and-public-sector transportation-and-logistics

Targeted regions: country_code:ir

Context

Meteor is a wiper that was used against Iranian government organizations, including Iranian Railways, the Ministry of Roads, and Urban Development systems, in July 2021. Meteor is likely a newer version of similar wipers called Stardust and Comet that were reportedly used by a group called "Indra" since at least 2019 against private companies in Syria.

Recent IoC activity

1 malicious indicator in Maltiverse are attributed to Meteor (S0688). The 1 most recently updated:

TypeIndicatorUpdatedSources
file sample 2aa6e42cb33ec3c132ffce425a92dfdb5e29d8ac112631aec068c8a78314d49b.zip 2026-08-27 1

Detection coverage

  • 672 Sigma rules

Malware & tools used

  • Service Stop (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Masquerade Task or Service (attack-pattern)
  • Clear Windows Event Logs (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Native API (attack-pattern)
  • Internal Defacement (attack-pattern)
  • Scheduled Task (attack-pattern)
  • PowerShell (attack-pattern)
  • Account Access Removal (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Hidden Window (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Inhibit System Recovery (attack-pattern)
  • Data Destruction (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • File Deletion (attack-pattern)
  • Process Discovery (attack-pattern)
  • Group Policy Modification (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)

Reports & references

  • twitter.com — 1541753913732366338 (report)
  • research.checkpoint.com — Indra Hackers Behind Recent Attacks On Iran (report)
  • CrowdStrike — The Anatomy Of Wiper Malware Part 1 (report)
  • CrowdStrike — The Anatomy Of Wiper Malware Part 3 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Meteor (report)
  • threatpost.com — 168262 (report)
  • labs.sentinelone.com — Meteorexpress Mysterious Wiper Paralyzes Iranian Trains With Epic Troll (report)
  • MITRE ATT&CK — S0688 (report)

External references