TF-MAL-ps1.lazywiper
📛 Threat Title
Malware family: LazyWiper
Description
ThreatFox malware family `ps1.lazywiper`. Printable name: LazyWiper.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
ps1.lazywiper
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/ps1.lazywiper
IOC database
- Type
- domain
- Value
ps1.lazywiper- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-ps1.lazywiper
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/ps1.lazywiper
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:arstechnica.com
Researchers on Friday said that Poland's electric grid was targeted by wiper malware , likely unleashed by Russia state hackers in an attempt to disrupt electricity delivery operations. A ...
-
web:attack.mitre.org
LazyWiper is a destructive malware observed targeting a manufacturing sector company during the 2025 Poland Wiper Attacks. LazyWiper is a native Windows PowerShell script that is believed to have been generated by a large language model (LLM).
-
web:bazaar.abuse.ch
A malware sample can be associated with only one malware family . The page below gives you an overview on malware samples that MalwareBazaar has identified as LazyWiper .
-
web:cert.pl
The malware used in the incident involving renewable energy farms was exe‐ cuted directly on the HMI machine. In contrast, in the CHP plant (DynoWiper) and the manufacturing sector company ( LazyWiper ), the malware was distrib‐ uted within the Active Directory domain via a PowerShell script executed on a domain controller.
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the LazyWiper malware family including references, samples and yara signatures.
-
web:misp-galaxy.org
LazyWiper is a destructive malware observed targeting a manufacturing sector company during the 2025 Poland Wiper Attacks. LazyWiper is a native Windows PowerShell script that is believed to have been generated by a large language model (LLM). LazyWiper overwrites files on the system using the C# function WriteRandomBytes () and can targets multiple specific file types by their extensions ...
-
web:research.checkpoint.com
The attackers conducted reconnaissance, firmware damage, lateral movement, and deployed DynoWiper and LazyWiper that corrupt files. Researchers have uncovered renewed Matanbuchus downloader campaigns using Microsoft Installer files disguised as legitimate installers, with frequent component changes to evade antivirus and machine learning detection.
-
web:www.infosecurity-magazine.com
The campaign against Polish energy assets is still being investigated, but Lipovsky said the timing of the "coordinated cyber-attack" might be deliberate. "It's the 10-year anniversary of the Sandworm-orchestrated attack against the Ukrainian power grid - the first ever malware -facilitated blackout in December 2015," he said.
-
web:www.pwndefend.com
Attackers gained access to operational technology (OT) systems, deploying wiper malware (including variants like DynoWiper and LazyWiper ), overwriting disks, deleting files, resetting configurations, and uploading corrupted firmware to "brick" certain hardware—resulting in permanent field-level impairment and complete loss of remote ...
-
web:www.rescana.com
The attackers deployed DynoWiper and LazyWiper malware to corrupt and delete files, overwrite firmware, and sabotage industrial devices. The attack on the CHP plant included long-term data theft and lateral movement, but the wiper malware was stopped by EDR systems.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.