Quarterly Journal of Information and Communication Technology ​

Design implementation and evolution of wiper malware in offensive cyber Operations: From Logical Data Destruction to Irrecoverable Erasure of Adversary Information

Document Type : Original Research Article

Authors

Department of Computer Engineering, Ha.C, Islamic Azad Unuversity, Hamedan, Iran

10.22034/apj.2026.2090974.1069
Abstract
Over the last decade, offensive cyber operations have evolved from intelligence-oriented campaigns toward destructive attacks targeting the availability and integrity of critical data and digital infrastructures. Among these threats, wiper malware has emerged as one of the most destructive cyber weapons due to its capability to permanently erase or corrupt information and disrupt organizational operations. This review paper aims to provide a comprehensive technical analysis of the design, implementation, and evolution of wiper malware by examining more than twenty documented real-world incidents, including Shamoon, NotPetya, WhisperGate, and AcidRain. Based on this analysis, a unified framework is proposed to classify data destruction techniques into three categories: physical-level destruction through storage controller commands such as ATA Secure Erase, block-level overwriting using fixed or random patterns, and logical-level corruption of metadata, partition tables, and file system structures. The study further analyzes the common architecture of modern wiper malware, including persistence mechanisms, command-and-control strategies, self-propagation techniques, parallel destruction modules, and anti-forensic capabilities. Comparative analysis demonstrates the gradual evolution of wiper malware from simple disk destruction toward sophisticated attacks targeting cloud infrastructures, virtualization platforms, and distributed storage environments. The review also identifies major technical challenges associated with forensic recovery, snapshot-based backup systems, and replicated cloud storage. As a practical contribution, the paper proposes a multilayer defensive framework based on Data Immutability, Write Once Read Many (WORM) hardware technologies, offline backup architectures, and kernel-level I/O anomaly detection to improve cyber resilience against destructive attacks. Overall, the findings highlight current technological trends, identify existing research gaps, and provide practical recommendations for developing more resilient storage architectures and effective protection mechanisms against future generations of destructive cyber threats.

Keywords


[1] A. Greenberg, Sandworm: A New Era of Cyberwar and the Hunt for the Kremlin's Most Dangerous Hackers. New                             York , NY, USA: Doubleday, 2019   
[2]  A. Cherepanov, “Bad Rabbit: a closer look at the new version of NotPetya,” ESET, WeLiveSecurity, White Paper, Oct. 2017. [Online]. Available: https://www.welivesecurity.com/wp-content/uploads/2017/10/bad-rabbit.pdf
[3]  Microsoft Threat Intelligence Center (MSTIC), “New destructive malware WhisperGate targeting organizations inUkraine,”MicrosoftSecurityBlog,Jan.2022.[Online]. Available:
https://www.microsoft.com/security/blog/2022/01/15/new-destructive-malware-whispergate-targeting-organizations-in-ukraine
[4]  L. O. Murchu, “AcidRain: A wiper targeting modems and routers in Ukraine,” Securelist (Kaspersky), Mar. 2022. [Online]. Available: https://securelist.com/acidrain-wiper-targeting-modems-routers-ukraine/111183/
[5] S. L. Garfinkel, “Digital forensics research: The next 10 years,” Digit. Investig., vol. 7, pp. S64–S73, Aug. 2010.
[6] M. Wei, L. M. Grupp, F. E. Spada, and S. Swanson, “Reliably erasing data from flash-based solid state drives,” in Proc. 9th USENIX Conf. File Storage Technol. (FAST), San Jose, CA, USA, 2011, pp. 8–21.
[7] Department of Defense (DoD), “National Industrial Security Program Operating Manual (NISPOM),” DoD 5220.22-M, Feb. 2006.
[8] J. Hellings, M. Sadoghi, and G. Alonso, “MVCC-based database corruption attacks and detection mechanisms,” Proc. VLDB Endowment, vol. 14, no. 5, pp. 789-801, Jan. 2021.
[9]  P. M. Chen and B. D. Noble, “When virtual is better than real: Operating system support for virtual    machines,” in Proc. 8th USENIX Symp. Oper. Syst. Des. Implement. (OSDI), San Diego, CA, USA, 2008, pp. 133–148.
[10] D. Kushwaha et al., “Lateral Movement Detection Using User Behavioral Analysis,” arXiv, 2022. 
[11]  M. F. U. R. A. Malik, “Detection latency of reverse sequential vs. forward sequential I/O patterns in enterprise storage systems,” in Proc. IEEE Int. Conf. Big Data (BigData), Seattle, WA, USA, 2022, pp. 4532-4540.
[12]  M. Graczyk, “Wiper malware: Evolution from Shamoon to WhisperGate,” SANS Institute InfoSec Reading Room, Tech. Rep. SANS-2023-WIPER, Feb. 2023.
[13]  R. Falcone, “Shamoon 2: Return of the wiper – technical analysis,” Palo Alto Networks Unit 42, Threat Brief, Nov. 2016. [Online]. Available: https://unit42.paloaltonetworks.com/shamoon-2-return-wiper/
[14]   Microsoft Security Response Center (MSRC), “CVE-2016-3309: Windows Task Scheduler elevation of privilege vulnerability,” Microsoft, Security Advisory, Aug. 2016.
[15]    A. Greenberg, “The untold story of NotPetya, the most devastating cyberattack in history,” Wired Magazine, Aug. 2018. [Online]. Available: https://www.wired.com/story/notpetya-cyberattack-ukraine-russia-code-crashed-the-world/
[16]    E. Kovacs, “WhisperGate wiper malware analyzed: Over 50 Ukrainian government systems hit,” SecurityWeek, Jan. 17, 2022. [Online]. Available: https://www.securityweek.com/whispergate-wiper-malware-analyzed-over-50-ukrainian-government-systems-hit
[17]    J. Menn, “How a cyberattack knocked out thousands of wind turbines in Germany,” Reuters, Apr. 4, 2022. [Online]. Available: https://www.reuters.com/business/energy/how-cyberattack-knocked-out-thousands-wind-turbines-germany-2022-04-04/
[18]    A. Bessani, R. Mendes, and T. Oliveira, “Cloud storage integrity checking: A survey,” ACM Comput. Surv., vol. 52, no. 2, pp. 1-35, Apr. 2019..
[20]    Amazon Web Services, “S3 Versioning documentation,” AWS Docs, 2023. [Online]. Available: https://docs.aws.amazon.com/AmazonS3/latest/userguide/Versioning.html
[21]    M. Graczyk, “Wiper Malware: Evolution from Shamoon to WhisperGate,” SANS Institute, 2023.
[22]  R. S. “Hardware vs. software immutability for ransomware and wiper protection,” IEEE Secur. Priv., vol. 20, no. 4, pp. 56-64, Aug. 2022.
[22]    LTO Consortium, “LTO-9 specification: WORM cartridge features,” LTO Technology Provider Guidelines, Rev. 2.0, 2022.
[23]    S. R. “Anomaly detection in block-level I/O streams for ransomware and wiper identification,” ACM Trans. Storage, vol. 18, no. 2, pp. 1-28, May 2022.
[24]  J. P. “Future directions in offensive cyber operations: Wiper malware 2030,” J. Inf. Warfare, vol. 22, no. 3, pp. 1-18, Summer 2023.
[25]  Trusted Computing Group, TPM 2.0 Library Specification, Family “2.0”, Level 00 Revision 01.59, Nov. 2019.
[26]  J. Kim and D. Park, “Wiper Malware: An Analysis of Recent Trends and Preventive Measures,” Journal of Defense and Security, vol. 4, no. 2, pp. 35–59, 2022, doi: 10.23425/defsec.2022.4.2.35.
[27]  M. Hirano and R. Kobayashi, “Machine Learning-based Ransomware Detection Using Low-level Memory Access Patterns Obtained From Live-forensic Hypervisor,” arXiv:2205.13765, 2022.
[28]  O. Y. Matsko, I. Y. Havryliuk, and H. H. Nayman, “Technical Analysis of the CaddyWiper Malware,” Modern Information Protection, no. 1, pp. 6–15, 2023, doi:10.31673/2409-7292.2023.010006.
[29]  A. Wolsey, “The State-of-the-Art in AI-Based Malware Detection Techniques: A Review,” arXiv:2210.11239, 2022.
[30]  X. Ling et al., “Adversarial Attacks against Windows PE Malware Detection: A Survey of the State-of-the-Art,” arXiv:2112.12310, 2021.
[31] Trusted Computing Group, “TPM 2.0 Library Specification,” Rev. 1.59, 2021.
[32]  ESET Research, “One Year of Wiper Attacks in Ukraine,” White Paper, 2023.
[33]  Fortinet FortiGuard Labs, “Global Threat Landscape Report 2023,” Fortinet, 2023.
[34]  IBM Security X-Force, “CaddyWiper: Third Wiper Malware Targeting Ukrainian Organizations,” IBM, 2022.
[35]  M.M.Shirmohmmadi and H.Yasinian and A.Gholami and F.Bahrami “Dealing with Ambiguity in Tech Projects: A Review of Tolerance for Ambiguity and its Development in IT Professionals” Arman Process Journal (APJ), vol.5, no.2,pp.1-15, Summer 2024.
[36]  MITRE ATT&CK, “AcidRain (S1125),” MITRE ATT&CK, 2024.
[37]  M.M.Shirmohmmadi and V.Mohmmadi ,” Analysis of Failed DNS Responses Using Neural Network in Botnet Detection”Arman Process Journal (APJ), vol.6, no.4,pp.1-11, Winter 2025.
[38]  M. Azadi, “Security Threats, Challenges, Procedures and Policies in Information Systems,” Arman Process Journal (APJ), vol. 4, no. 3, pp. 34–42, Autumn 2023.
[39]  H. Mansouri, “Approaches to Address the Challenge of Intrusion in Cloud Computing Services,” Arman Process Journal (APJ), vol. 6, no. 3, pp. 76–88, Autumn 2025.
[40]  R. Ghaffari, “Improving Security and Privacy in the Internet of Things Based on Blockchain Technology,” Arman Process Journal (APJ), vol. 5, no. 4, pp. 15–24, Winter 2025.