<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE ArticleSet PUBLIC "-//NLM//DTD PubMed 2.7//EN" "https://dtd.nlm.nih.gov/ncbi/pubmed/in/PubMed.dtd">
<ArticleSet>
<Article>
<Journal>
				<PublisherName></PublisherName>
				<JournalTitle>فصلنامه تخصصی آرمان پردازش</JournalTitle>
				<Issn>2783-1361</Issn>
				<Volume>7</Volume>
				<Issue>1</Issue>
				<PubDate PubStatus="epublish">
					<Year>2026</Year>
					<Month>04</Month>
					<Day>21</Day>
				</PubDate>
			</Journal>
<ArticleTitle>Design implementation and evolution of wiper malware in offensive cyber Operations: From Logical Data Destruction to Irrecoverable Erasure of Adversary Information</ArticleTitle>
<VernacularTitle>طراحی پیاده سازی و تکامل بدافزارهای پاکساز در عملیات های سایبری تهاجمی از تخریب مطقی داده تا حذف غیرقابل بازیابی اطلاعات دشمن</VernacularTitle>
			<FirstPage>76</FirstPage>
			<LastPage>91</LastPage>
			<ELocationID EIdType="pii">738083</ELocationID>
			
<ELocationID EIdType="doi">10.22034/apj.2026.2090974.1069</ELocationID>
			
			<Language>FA</Language>
<AuthorList>
<Author>
					<FirstName>نگار</FirstName>
					<LastName>عطائیان</LastName>
<Affiliation>گروه مهندسی کامپیوتر، واحد همدان، دانشگاه ازاد اسلامی،همدان، ایران</Affiliation>

</Author>
<Author>
					<FirstName>محمدمهدی</FirstName>
					<LastName>شیرمحمدی</LastName>
<Affiliation>گروه مهندسی کامپیوتر، واحد همدان، دانشگاه ازاد اسلامی، همدان، ایران</Affiliation>

</Author>
</AuthorList>
				<PublicationType>Journal Article</PublicationType>
		<Abstract>Over the last decade, offensive cyber operations have evolved from intelligence-oriented campaigns toward destructive attacks targeting the availability and integrity of critical data and digital infrastructures. Among these threats, wiper malware has emerged as one of the most destructive cyber weapons due to its capability to permanently erase or corrupt information and disrupt organizational operations. This review paper aims to provide a comprehensive technical analysis of the design, implementation, and evolution of wiper malware by examining more than twenty documented real-world incidents, including Shamoon, NotPetya, WhisperGate, and AcidRain. Based on this analysis, a unified framework is proposed to classify data destruction techniques into three categories: physical-level destruction through storage controller commands such as ATA Secure Erase, block-level overwriting using fixed or random patterns, and logical-level corruption of metadata, partition tables, and file system structures. The study further analyzes the common architecture of modern wiper malware, including persistence mechanisms, command-and-control strategies, self-propagation techniques, parallel destruction modules, and anti-forensic capabilities. Comparative analysis demonstrates the gradual evolution of wiper malware from simple disk destruction toward sophisticated attacks targeting cloud infrastructures, virtualization platforms, and distributed storage environments. The review also identifies major technical challenges associated with forensic recovery, snapshot-based backup systems, and replicated cloud storage. As a practical contribution, the paper proposes a multilayer defensive framework based on Data Immutability, Write Once Read Many (WORM) hardware technologies, offline backup architectures, and kernel-level I/O anomaly detection to improve cyber resilience against destructive attacks. Overall, the findings highlight current technological trends, identify existing research gaps, and provide practical recommendations for developing more resilient storage architectures and effective protection mechanisms against future generations of destructive cyber threats.</Abstract>
			<OtherAbstract Language="FA">در دهه اخیر، عملیات‌های سایبری تهاجمی از فعالیت‌های صرفاً مبتنی بر جاسوسی به سمت حملات مخرب با هدف از بین بردن دسترس‌پذیری و یکپارچگی داده‌ها و زیرساخت‌های حیاتی تحول یافته‌اند. در این میان، بدافزارهای پاک‌ساز به دلیل توانایی در حذف دائمی یا تخریب غیرقابل‌بازیابی اطلاعات، به یکی از مهم‌ترین ابزارهای حملات سایبری دولتی و تخریب زیرساخت‌های داده‌محور تبدیل شده‌اند. هدف این مقاله مروری، ارائه تحلیلی جامع از طراحی، پیاده‌سازی و روند تکامل بدافزارهای پاک‌ساز بر پایه بررسی بیش از ۲۰ نمونه واقعی، از جمله شامون، نات پتیا، ویسپرگیت و اسیدرین است. بر اساس این بررسی، چارچوبی یکپارچه برای طبقه‌بندی روش‌های تخریب داده در سه سطح فیزیکی سطح بلوکی (بازنویسی داده‌ها با الگوهای ثابت یا تصادفی) و سطح منطقی (تخریب فراداده، جدول پارتیشن و ساختار سیستم فایل) ارائه شده است. علاوه بر این معماری مشترک این بدافزارها شامل سازوکارهای ماندگاری، فرمان و کنترل، انتشار خودکار، ماژول‌های تخریب موازی و قابلیت‌های ضدپزشکی قانونی مورد تحلیل قرار گرفته است. نتایج این مطالعه نشان می‌دهد که نسل جدید بدافزارهای پاک‌ساز از تخریب ساده دیسک به سمت حمله به زیرساخت‌های ابری، محیط‌های مجازی‌سازی و سامانه‌های ذخیره‌سازی توزیع‌شده حرکت کرده‌اند. از نوآوری‌های این پژوهش، ارائه یک چارچوب تحلیلی یکپارچه برای مقایسه روش‌های تخریب داده و پیشنهاد یک مدل دفاعی چندلایه مبتنی بر تغییرناپذیری داده فناوری WORM، پشتیبان‌گیری برون‌خط و آشکارسازی ناهنجاری‌های ورودی/خروجی در سطح هسته سیستم‌عامل است. یافته‌های این پژوهش علاوه بر شناسایی روندهای نوظهور و شکاف‌های موجود، می‌تواند در طراحی سامانه‌های ذخیره‌سازی مقاوم و توسعه راهکارهای مؤثر برای مقابله با نسل آینده بدافزارهای پاک‌ساز مورد استفاده قرار گیرد</OtherAbstract>
		<ObjectList>
			<Object Type="keyword">
			<Param Name="value">پیاده سازی</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">بد افزار</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">عملیات سایبری</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">بازیابی اطلاعات</Param>
			</Object>
		</ObjectList>
<ArchiveCopySource DocType="pdf">https://www.armanprocessjournal.ir/article_738083_53c7141fc08f995f8d66d3a93580ace0.pdf</ArchiveCopySource>
</Article>
</ArticleSet>
