فصلنامه تخصصی فناوری اطلاعات و ارتباطات

طراحی پیاده سازی و تکامل بدافزارهای پاکساز در عملیات های سایبری تهاجمی از تخریب مطقی داده تا حذف غیرقابل بازیابی اطلاعات دشمن

نوع مقاله : مقاله پژوهشی

نویسندگان

1 گروه مهندسی کامپیوتر، واحد همدان، دانشگاه ازاد اسلامی،همدان، ایران

2 گروه مهندسی کامپیوتر، واحد همدان، دانشگاه ازاد اسلامی، همدان، ایران

10.22034/apj.2026.2090974.1069
چکیده
در دهه اخیر، عملیات‌های سایبری تهاجمی از فعالیت‌های صرفاً مبتنی بر جاسوسی به سمت حملات مخرب با هدف از بین بردن دسترس‌پذیری و یکپارچگی داده‌ها و زیرساخت‌های حیاتی تحول یافته‌اند. در این میان، بدافزارهای پاک‌ساز به دلیل توانایی در حذف دائمی یا تخریب غیرقابل‌بازیابی اطلاعات، به یکی از مهم‌ترین ابزارهای حملات سایبری دولتی و تخریب زیرساخت‌های داده‌محور تبدیل شده‌اند. هدف این مقاله مروری، ارائه تحلیلی جامع از طراحی، پیاده‌سازی و روند تکامل بدافزارهای پاک‌ساز بر پایه بررسی بیش از ۲۰ نمونه واقعی، از جمله شامون، نات پتیا، ویسپرگیت و اسیدرین است. بر اساس این بررسی، چارچوبی یکپارچه برای طبقه‌بندی روش‌های تخریب داده در سه سطح فیزیکی سطح بلوکی (بازنویسی داده‌ها با الگوهای ثابت یا تصادفی) و سطح منطقی (تخریب فراداده، جدول پارتیشن و ساختار سیستم فایل) ارائه شده است. علاوه بر این معماری مشترک این بدافزارها شامل سازوکارهای ماندگاری، فرمان و کنترل، انتشار خودکار، ماژول‌های تخریب موازی و قابلیت‌های ضدپزشکی قانونی مورد تحلیل قرار گرفته است. نتایج این مطالعه نشان می‌دهد که نسل جدید بدافزارهای پاک‌ساز از تخریب ساده دیسک به سمت حمله به زیرساخت‌های ابری، محیط‌های مجازی‌سازی و سامانه‌های ذخیره‌سازی توزیع‌شده حرکت کرده‌اند. از نوآوری‌های این پژوهش، ارائه یک چارچوب تحلیلی یکپارچه برای مقایسه روش‌های تخریب داده و پیشنهاد یک مدل دفاعی چندلایه مبتنی بر تغییرناپذیری داده فناوری WORM، پشتیبان‌گیری برون‌خط و آشکارسازی ناهنجاری‌های ورودی/خروجی در سطح هسته سیستم‌عامل است. یافته‌های این پژوهش علاوه بر شناسایی روندهای نوظهور و شکاف‌های موجود، می‌تواند در طراحی سامانه‌های ذخیره‌سازی مقاوم و توسعه راهکارهای مؤثر برای مقابله با نسل آینده بدافزارهای پاک‌ساز مورد استفاده قرار گیرد

کلیدواژه‌ها


عنوان مقاله English

Design implementation and evolution of wiper malware in offensive cyber Operations: From Logical Data Destruction to Irrecoverable Erasure of Adversary Information

نویسندگان English

Negar Ataeian 1
Mohammadmehdi Shirmohammadi 2
1 Department of Computer Engineering, Ha.C, Islamic Azad Unuversity, Hamedan, Iran
2 Department of Computer Engineering, Ha.C, Islamic Azad Unuversity, Hamedan, Iran
چکیده English

Over the last decade, offensive cyber operations have evolved from intelligence-oriented campaigns toward destructive attacks targeting the availability and integrity of critical data and digital infrastructures. Among these threats, wiper malware has emerged as one of the most destructive cyber weapons due to its capability to permanently erase or corrupt information and disrupt organizational operations. This review paper aims to provide a comprehensive technical analysis of the design, implementation, and evolution of wiper malware by examining more than twenty documented real-world incidents, including Shamoon, NotPetya, WhisperGate, and AcidRain. Based on this analysis, a unified framework is proposed to classify data destruction techniques into three categories: physical-level destruction through storage controller commands such as ATA Secure Erase, block-level overwriting using fixed or random patterns, and logical-level corruption of metadata, partition tables, and file system structures. The study further analyzes the common architecture of modern wiper malware, including persistence mechanisms, command-and-control strategies, self-propagation techniques, parallel destruction modules, and anti-forensic capabilities. Comparative analysis demonstrates the gradual evolution of wiper malware from simple disk destruction toward sophisticated attacks targeting cloud infrastructures, virtualization platforms, and distributed storage environments. The review also identifies major technical challenges associated with forensic recovery, snapshot-based backup systems, and replicated cloud storage. As a practical contribution, the paper proposes a multilayer defensive framework based on Data Immutability, Write Once Read Many (WORM) hardware technologies, offline backup architectures, and kernel-level I/O anomaly detection to improve cyber resilience against destructive attacks. Overall, the findings highlight current technological trends, identify existing research gaps, and provide practical recommendations for developing more resilient storage architectures and effective protection mechanisms against future generations of destructive cyber threats.

کلیدواژه‌ها English

Malware
Wiper Malware
Implementation
Cyber Operations
Data Recovery
[1] A. Greenberg, Sandworm: A New Era of Cyberwar and the Hunt for the Kremlin's Most Dangerous Hackers. NewYork , NY, USA: Doubleday, 2019   
[2]  A. Cherepanov, “Bad Rabbit: a closer look at the new version of NotPetya,” ESET, WeLiveSecurity, White Paper, Oct. 2017. [Online]. Available: https://www.welivesecurity.com/wp-content/uploads/2017/10/bad-rabbit.pdf
[3]  Microsoft Threat Intelligence Center (MSTIC), “New destructive malware WhisperGate targeting organizations inUkraine,”MicrosoftSecurityBlog,Jan.2022.[Online]. Available:
https://www.microsoft.com/security/blog/2022/01/15/new-destructive-malware-whispergate-targeting-organizations-in-ukraine
[4]  L. O. Murchu, “AcidRain: A wiper targeting modems and routers in Ukraine,” Securelist (Kaspersky), Mar. 2022. [Online]. Available: https://securelist.com/acidrain-wiper-targeting-modems-routers-ukraine/111183/
[5] S. L. Garfinkel, “Digital forensics research: The next 10 years,” Digit. Investig., vol. 7, pp. S64–S73, Aug. 2010.
[6] M. Wei, L. M. Grupp, F. E. Spada, and S. Swanson, “Reliably erasing data from flash-based solid state drives,” in Proc. 9th USENIX Conf. File Storage Technol. (FAST), San Jose, CA, USA, 2011, pp. 8–21.
[7] Department of Defense (DoD), “National Industrial Security Program Operating Manual (NISPOM),” DoD 5220.22-M, Feb. 2006.
[8] J. Hellings, M. Sadoghi, and G. Alonso, “MVCC-based database corruption attacks and detection mechanisms,” Proc. VLDB Endowment, vol. 14, no. 5, pp. 789-801, Jan. 2021.
[9]  P. M. Chen and B. D. Noble, “When virtual is better than real: Operating system support for virtual    machines,” in Proc. 8th USENIX Symp. Oper. Syst. Des. Implement. (OSDI), San Diego, CA, USA, 2008, pp. 133–148.
[10] D. Kushwaha et al., “Lateral Movement Detection Using User Behavioral Analysis,” arXiv, 2022. 
[11]  M. F. U. R. A. Malik, “Detection latency of reverse sequential vs. forward sequential I/O patterns in enterprise storage systems,” in Proc. IEEE Int. Conf. Big Data (BigData), Seattle, WA, USA, 2022, pp. 4532-4540.
[12]  M. Graczyk, “Wiper malware: Evolution from Shamoon to WhisperGate,” SANS Institute InfoSec Reading Room, Tech. Rep. SANS-2023-WIPER, Feb. 2023.
[13]  R. Falcone, “Shamoon 2: Return of the wiper – technical analysis,” Palo Alto Networks Unit 42, Threat Brief, Nov. 2016. [Online]. Available: https://unit42.paloaltonetworks.com/shamoon-2-return-wiper/
[14]   Microsoft Security Response Center (MSRC), “CVE-2016-3309: Windows Task Scheduler elevation of privilege vulnerability,” Microsoft, Security Advisory, Aug. 2016.
[15]    A. Greenberg, “The untold story of NotPetya, the most devastating cyberattack in history,” Wired Magazine, Aug. 2018. [Online]. Available: https://www.wired.com/story/notpetya-cyberattack-ukraine-russia-code-crashed-the-world/
[16]    E. Kovacs, “WhisperGate wiper malware analyzed: Over 50 Ukrainian government systems hit,” SecurityWeek, Jan. 17, 2022. [Online]. Available: https://www.securityweek.com/whispergate-wiper-malware-analyzed-over-50-ukrainian-government-systems-hit
[17]    J. Menn, “How a cyberattack knocked out thousands of wind turbines in Germany,” Reuters, Apr. 4, 2022. [Online]. Available: https://www.reuters.com/business/energy/how-cyberattack-knocked-out-thousands-wind-turbines-germany-2022-04-04/
[18]    A. Bessani, R. Mendes, and T. Oliveira, “Cloud storage integrity checking: A survey,” ACM Comput. Surv., vol. 52, no. 2, pp. 1-35, Apr. 2019..
[20]    Amazon Web Services, “S3 Versioning documentation,” AWS Docs, 2023. [Online]. Available: https://docs.aws.amazon.com/AmazonS3/latest/userguide/Versioning.html
[21]    M. Graczyk, “Wiper Malware: Evolution from Shamoon to WhisperGate,” SANS Institute, 2023.
[22]  R. S. “Hardware vs. software immutability for ransomware and wiper protection,” IEEE Secur. Priv., vol. 20, no. 4, pp. 56-64, Aug. 2022.
[22]    LTO Consortium, “LTO-9 specification: WORM cartridge features,” LTO Technology Provider Guidelines, Rev. 2.0, 2022.
[23]    S. R. “Anomaly detection in block-level I/O streams for ransomware and wiper identification,” ACM Trans. Storage, vol. 18, no. 2, pp. 1-28, May 2022.
[24]  J. P. “Future directions in offensive cyber operations: Wiper malware 2030,” J. Inf. Warfare, vol. 22, no. 3, pp. 1-18, Summer 2023.
[25]  Trusted Computing Group, TPM 2.0 Library Specification, Family “2.0”, Level 00 Revision 01.59, Nov. 2019.
[26]  J. Kim and D. Park, “Wiper Malware: An Analysis of Recent Trends and Preventive Measures,” Journal of Defense and Security, vol. 4, no. 2, pp. 35–59, 2022, doi: 10.23425/defsec.2022.4.2.35.
[27]  M. Hirano and R. Kobayashi, “Machine Learning-based Ransomware Detection Using Low-level Memory Access Patterns Obtained From Live-forensic Hypervisor,” arXiv:2205.13765, 2022.
[28]  O. Y. Matsko, I. Y. Havryliuk, and H. H. Nayman, “Technical Analysis of the CaddyWiper Malware,” Modern Information Protection, no. 1, pp. 6–15, 2023, doi:10.31673/2409-7292.2023.010006.
[29]  A. Wolsey, “The State-of-the-Art in AI-Based Malware Detection Techniques: A Review,” arXiv:2210.11239, 2022.
[30]  X. Ling et al., “Adversarial Attacks against Windows PE Malware Detection: A Survey of the State-of-the-Art,” arXiv:2112.12310, 2021.
[31] Trusted Computing Group, “TPM 2.0 Library Specification,” Rev. 1.59, 2021.
[32]  ESET Research, “One Year of Wiper Attacks in Ukraine,” White Paper, 2023.
[33]  Fortinet FortiGuard Labs, “Global Threat Landscape Report 2023,” Fortinet, 2023.
[34]  IBM Security X-Force, “CaddyWiper: Third Wiper Malware Targeting Ukrainian Organizations,” IBM, 2022.
[35]  M.M.Shirmohmmadi and H.Yasinian and A.Gholami and F.Bahrami “Dealing with Ambiguity in Tech Projects: A Review of Tolerance for Ambiguity and its Development in IT Professionals” Arman Process Journal (APJ), vol.5, no.2,pp.1-15, Summer 2024.
[36]  MITRE ATT&CK, “AcidRain (S1125),” MITRE ATT&CK, 2024.
[37]  M.M.Shirmohmmadi and V.Mohmmadi ,” Analysis of Failed DNS Responses Using Neural Network in Botnet Detection”Arman Process Journal (APJ), vol.6, no.4,pp.1-11, Winter 2025.
[38]  M. Azadi, “Security Threats, Challenges, Procedures and Policies in Information Systems,” Arman Process Journal (APJ), vol. 4, no. 3, pp. 34–42, Autumn 2023.
[39]  H. Mansouri, “Approaches to Address the Challenge of Intrusion in Cloud Computing Services,” Arman Process Journal (APJ), vol. 6, no. 3, pp. 76–88, Autumn 2025.
[40]  R. Ghaffari, “Improving Security and Privacy in the Internet of Things Based on Blockchain Technology,” Arman Process Journal (APJ), vol. 5, no. 4, pp. 15–24, Winter 2025.