What is a wiper?¶
The practical answer¶
A wiper is malicious software or activity designed to destroy data, systems or their ability to operate.
The key evidential caution¶
The dangerous assumption is that any severe data loss proves a wiper was used.
It may not.
A wiper may:
Key points¶
- overwrite files
- damage file systems
- erase boot records
- destroy configuration
- remove recovery data
- delete cloud resources
- render devices unbootable
- corrupt large numbers of files
Evidence to preserve¶
Investigators should preserve:
Key points¶
- the suspected wiper file or script
- hash and path
- process activity
- command line
- account context
- targeted files or devices
- start time
- system errors
- affected storage
- network or control activity
- recovery results
Some ransomware can behave like a wiper if decryption is impossible or deliberately withheld.
Evidential limits¶
Likewise, a destructive script may use legitimate administration tools rather than specialist malware.
The label should follow the observed destructive behaviour and technical analysis.
Do not execute a suspected wiper on production or unprotected systems.
The presence of a wiper sample proves capability or preparation.
Process and storage evidence are needed to prove execution and effect.
Some wipers imitate ransomware by displaying a demand or changing file extensions even though reliable recovery is impossible. The presence of a note should not decide the label. Examine whether encryption keys, recovery logic and file transformation support genuine recoverability.
A wiper may be delivered through the same remote-management, scripting or deployment tools used legitimately by the organisation. Preserve the upstream job, operator account and command source, because the affected endpoint may record only a trusted local process.
Operational takeaway¶
Prove wiper execution from process, storage and system damage evidence, and distinguish destructive malware from corruption, failed recovery and ordinary deletion.