Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is a wiper?

A wiper is malicious software or activity intended to destroy data or make systems inoperable. Severe loss alone does not prove a wiper: corruption, deletion, failed recovery and other faults can create similar damage.

Preserve the suspected file or script, hash, path, command line, process chain, account, targeted storage, start time, errors, control traffic and recovery result. A sample establishes capability; execution and filesystem or boot damage establish use and effect.

Destruction may be delivered through trusted scripting, deployment or management tools. Retain the upstream job, operator and command source rather than attributing endpoint activity to the local service account.

Distinguish wiping from apparent ransomware

Some wipers display a demand or change extensions while offering no workable recovery. Examine file transformation, key handling and recovery logic instead of letting the note determine the label.

Do not execute suspected destructive code on production or unprotected systems. State whether evidence proves preparation, execution, recoverability or irreversible damage separately.

Key takeaway

Prove wiper use by connecting destructive execution to specific storage damage, distinguishing it from corruption, ordinary deletion and ransomware appearance.

Reference: CIM-226Cyber Incidents & Offender Methods