LazyWiper
MITRE ATT&CK: S9039 View on attack.mitre.org
Aliases: LazyWiper
- Malware type
- wiper
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 14:38:40
Targeted industries: manufacturing
Targeted regions: country_code:pl
Context
LazyWiper is a destructive malware observed targeting a manufacturing sector company during the 2025 Poland Wiper Attacks. LazyWiper is a native Windows PowerShell script that is believed to have been generated by a large language model (LLM). LazyWiper overwrites files on the system using the C# function `WriteRandomBytes()` and can target multiple specific file types by their extensions.
Detection coverage
- 406 Sigma rules
Malware & tools used
- File and Directory Discovery (attack-pattern)
- Selective Exclusion (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- PowerShell (attack-pattern)
- Execution Guardrails (attack-pattern)
- System Information Discovery (attack-pattern)
- Data Destruction (attack-pattern)
- Artificial Intelligence (attack-pattern)
Used by threat actors
- 2025 Poland Wiper Attacks (campaign)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Ps1.Lazywiper (report)
- cert.pl — Cert Polska Energy Sector Incident Report 2025 (report)
- MITRE ATT&CK — S9039 (report)