LazyWiper

MITRE ATT&CK: S9039 View on attack.mitre.org

Aliases: LazyWiper

Malware type
wiper
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 14:38:40

Targeted industries: manufacturing

Targeted regions: country_code:pl

Context

LazyWiper is a destructive malware observed targeting a manufacturing sector company during the 2025 Poland Wiper Attacks. LazyWiper is a native Windows PowerShell script that is believed to have been generated by a large language model (LLM). LazyWiper overwrites files on the system using the C# function `WriteRandomBytes()` and can target multiple specific file types by their extensions.

Detection coverage

  • 406 Sigma rules

Malware & tools used

  • File and Directory Discovery (attack-pattern)
  • Selective Exclusion (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • PowerShell (attack-pattern)
  • Execution Guardrails (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Data Destruction (attack-pattern)
  • Artificial Intelligence (attack-pattern)

Used by threat actors

  • 2025 Poland Wiper Attacks (campaign)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Ps1.Lazywiper (report)
  • cert.pl — Cert Polska Energy Sector Incident Report 2025 (report)
  • MITRE ATT&CK — S9039 (report)

External references