s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-ps1.lazywiper

📛 Threat Title

Malware family: LazyWiper

Category: LazyWiper First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `ps1.lazywiper`. Printable name: LazyWiper.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain ps1.lazywiper VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/ps1.lazywiper

IOC database

Type
domain
Value
ps1.lazywiper
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-ps1.lazywiper

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/ps1.lazywiper

References (1)

Remediations (10)

  • web:arstechnica.com

    Researchers on Friday said that Poland's electric grid was targeted by wiper malware , likely unleashed by Russia state hackers in an attempt to disrupt electricity delivery operations. A ...

  • web:attack.mitre.org

    LazyWiper is a destructive malware observed targeting a manufacturing sector company during the 2025 Poland Wiper Attacks. LazyWiper is a native Windows PowerShell script that is believed to have been generated by a large language model (LLM).

  • web:bazaar.abuse.ch

    A malware sample can be associated with only one malware family . The page below gives you an overview on malware samples that MalwareBazaar has identified as LazyWiper .

  • web:cert.pl

    The malware used in the incident involving renewable energy farms was exe‐ cuted directly on the HMI machine. In contrast, in the CHP plant (DynoWiper) and the manufacturing sector company ( LazyWiper ), the malware was distrib‐ uted within the Active Directory domain via a PowerShell script executed on a domain controller.

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the LazyWiper malware family including references, samples and yara signatures.

  • web:misp-galaxy.org

    LazyWiper is a destructive malware observed targeting a manufacturing sector company during the 2025 Poland Wiper Attacks. LazyWiper is a native Windows PowerShell script that is believed to have been generated by a large language model (LLM). LazyWiper overwrites files on the system using the C# function WriteRandomBytes () and can targets multiple specific file types by their extensions ...

  • web:research.checkpoint.com

    The attackers conducted reconnaissance, firmware damage, lateral movement, and deployed DynoWiper and LazyWiper that corrupt files. Researchers have uncovered renewed Matanbuchus downloader campaigns using Microsoft Installer files disguised as legitimate installers, with frequent component changes to evade antivirus and machine learning detection.

  • web:www.infosecurity-magazine.com

    The campaign against Polish energy assets is still being investigated, but Lipovsky said the timing of the "coordinated cyber-attack" might be deliberate. "It's the 10-year anniversary of the Sandworm-orchestrated attack against the Ukrainian power grid - the first ever malware -facilitated blackout in December 2015," he said.

  • web:www.pwndefend.com

    Attackers gained access to operational technology (OT) systems, deploying wiper malware (including variants like DynoWiper and LazyWiper ), overwriting disks, deleting files, resetting configurations, and uploading corrupted firmware to "brick" certain hardware—resulting in permanent field-level impairment and complete loss of remote ...

  • web:www.rescana.com

    The attackers deployed DynoWiper and LazyWiper malware to corrupt and delete files, overwrite firmware, and sabotage industrial devices. The attack on the CHP plant included long-term data theft and lateral movement, but the wiper malware was stopped by EDR systems.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.