RoarBAT

Malware type
wiper
Profile updated
2026-07-07 12:44:59

Context

According to SOCRadar, this is a batch script that uses WinRAR to delete files with target file extensions from a disk.

Reports & references

  • services.google.com — Apt44 Unearthing Sandworm (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Roar Bat (report)
  • socradar.io — Sandworm Attackers Use Winrar To Wipe Data From Government Devices (report)

External references