Skip to content
CIM-226 Cyber Incidents & Offender Methods

What is a wiper?

The practical answer

A wiper is malicious software or activity designed to destroy data, systems or their ability to operate.

The key evidential caution

The dangerous assumption is that any severe data loss proves a wiper was used.

It may not.

A wiper may:

Key points

  • overwrite files
  • damage file systems
  • erase boot records
  • destroy configuration
  • remove recovery data
  • delete cloud resources
  • render devices unbootable
  • corrupt large numbers of files

Evidence to preserve

Investigators should preserve:

Key points

  • the suspected wiper file or script
  • hash and path
  • process activity
  • command line
  • account context
  • targeted files or devices
  • start time
  • system errors
  • affected storage
  • network or control activity
  • recovery results

Some ransomware can behave like a wiper if decryption is impossible or deliberately withheld.

Evidential limits

Likewise, a destructive script may use legitimate administration tools rather than specialist malware.

The label should follow the observed destructive behaviour and technical analysis.

Do not execute a suspected wiper on production or unprotected systems.

The presence of a wiper sample proves capability or preparation.

Process and storage evidence are needed to prove execution and effect.

Some wipers imitate ransomware by displaying a demand or changing file extensions even though reliable recovery is impossible. The presence of a note should not decide the label. Examine whether encryption keys, recovery logic and file transformation support genuine recoverability.

A wiper may be delivered through the same remote-management, scripting or deployment tools used legitimately by the organisation. Preserve the upstream job, operator account and command source, because the affected endpoint may record only a trusted local process.

Operational takeaway

Prove wiper execution from process, storage and system damage evidence, and distinguish destructive malware from corruption, failed recovery and ordinary deletion.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.