Malware.View on attack.mitre.org
LazyWiper is a destructive malware observed targeting a manufacturing sector company during the 2025 Poland Wiper Attacks. LazyWiper is a native Windows PowerShell script that is believed to have been generated by a large language model (LLM). LazyWiper overwrites files on the system using the C# function `WriteRandomBytes()` and can target multiple specific file types by their extensions.
| Technique | Procedure example |
|---|---|
| T1059.001 PowerShell |
LazyWiper has used PowerShell to enable data destruction on targeted systems. |
| T1082 System Information Discovery |
LazyWiper has used `[System.Net.Dns]::GetHostName()` and `$env:COMPUTERNAME` to enumerate the hostname of a system and determine if it is a domain controller. |
| T1083 File and Directory Discovery |
LazyWiper can specifically target multiple files by extension including: .rar, .tar.gz, .zip, .7z, .json, .bcp, .bak, .gho, .erf, .edb, .onepkg, .pst, and .ldiff. |
| T1480 Execution Guardrails |
LazyWiper can halt execution if `[System.Net.Dns]::GetHostName()` or `$env:COMPUTERNAME` contains `“pe-dc”`. |
| T1485 Data Destruction |
LazyWiper has overwritten files with pseudorandom 32‑byte sequences written at 16‑byte intervals making the file unrecoverable. |
| T1588.007 Artificial Intelligence |
LazyWiper is believed to have been generated by a large language model (LLM) due to the non-sensical comments in the code. |
| T1679 Selective Exclusion |
LazyWiper can enumerate the hostname of the system to determine if it is a domain controller and exclude it from being wiped if so. |
| T1685 Disable or Modify Tools |
LazyWiper can disable Microsoft Windows Defender Real-Time Monitoring with the `Set-MpPreference` cmdlet. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.