An unknown wiper malware , codenamed Lotus , has come to light through Kaspersky research , revealing a particularly dangerous campaign of attacks against energy and utility organizations in Venezuela . This malware is not limited to simple data breach or theft , but is designed with a clear goal: to completely destroy systems , making them impossible to recover.

According to the findings, Lotus was first detected on a public platform in mid-December 2025, and its activity is temporally linked to a period of heightened geopolitical tensions in the region. While there is no official confirmation of specific targets, the timing of cyberattacks on state organizations, such as oil company PDVSA, heightens concerns about its use in cyberwarfare operations.
See also: Unsecured Perforce servers expose sensitive data
How Lotus works and why it is so dangerous
Lotus belongs to the category of wipers, i.e. malicious programs whose primary purpose is to delete data. However, this particular implementation stands out for complexity and persistence . Before the final payload is activated, the attackers use a series of scripts that prepare the target system, disabling critical functions and weakening defenses.
In the first stage, a script disables essential Windows services and coordinates the execution of the attack on networks connected to the same domain. Then, a second script proceeds to more aggressive actions, such as disabling user accounts , logging out active sessions, and completely stopping network communication. In this way, the system is isolated and becomes more vulnerable to the final blow.

Total destruction without return
The most worrying aspect of Lotus is its ability to cause irreversible damage. The malware does not stop at deleting files, but goes deeper into the system. Using tools like diskpart and fsutil, it overwrites the contents of disks with zeros, while also filling up the available space to prevent any attempt at data recovery.
See also: Data breaches at healthcare organizations affect 600,000 people
At a more advanced level, Lotus interacts directly with the hardware, erasing physical drives and removing critical data, such as Windows restore and activity logs. This process is repeated multiple times, ensuring that the system remains inoperable even after a reboot.
Indications and methods of early detection
Kaspersky notes that there are some warning signs that can help detect such an attack early. These include unusual changes to user accounts, disabling of services and network interfaces, and unexpected use of disk management tools.
Particular attention is also required to changes related to NETLOGON or the UI0Detect, as these may be part of the preparation for the final attack. Early identification of these actions can prevent the malware from fully activating.
See also: NGate malware: Targets Android via fake HandyPay app

The broader picture of cyberattacks on critical infrastructure
The emergence of Lotus is part of a broader trend of increasing attacks on critical infrastructure, particularly in sectors such as energy and transportation. Unlike ransomware, which is primarily aimed at financial gain, wipers are often used in geopolitical contexts, aiming to disrupt operations and cause chaos.
The incident highlights the need for enhanced cybersecurity measures, especially in organizations that manage critical services. Maintaining regular and isolated backups, as well as constant monitoring of systems, are key defense practices against such sophisticated threats.
Source: www.bleepingcomputer.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
