
Security researchers have discovered a new disk-wiping malware, created by an Iraqi hacker and called “ZeroCleare,” that can destroy disk partitions on network devices.
The malware has targeted multiple sectors, including energy and infrastructure, primarily in Middle Eastern countries. It is believed that the attacks are being carried out by a government- backed Iranian hacking group .
According to researchers, ZeroCleare bears similarities to another disk-wiping malware, Shamoon, which carried out its attacks using the image of a burning dollar.
ZeroCleare's main goal is to replace Master Boot Record (MBR) files and disk partitions on Windows. Using EldoS RawDisk, a legitimate tool for interacting with files, disks, and partitions, it attempts to clean up MBR files and damaged disk partitions.
The Middle East often falls victim to such attacks in the energy and industrial sectors, while there are also many cases where various countries attack the economies of their rivals.
ZeroCleare comes in two versions, one for each Windows architecture (32-bit and 64-bit), but only one was functional. The 32-bit version supposedly worked, with the EldoS RawDisk program installed.
Researchers observed several files in the malware arsenal that infected devices with the ZeroCleare malware and spread through compromised networks.
In the final stage, ZeroCleare will be executed automatically, delivering the file name ClientUpdate.exe, running with the legitimate license key for the EldoS RawDisk program and proceeding to the disk cleanup phase.
