Lotus Wiper targeting of Venezuela energy sector and suspected link to PDVSA cyberattack
- Event Year
- 2025
- Reliability
- Likely But Unconfirmed
- Country
- Venezuela
- Industry
- Petroleum
- Attack Type
- Targeted Attack
Description
In April 2026, Kaspersky disclosed Lotus Wiper, a previously undocumented destructive malware family built for a targeted operation against Venezuela's energy and utilities sector. The artifacts were uploaded from a Venezuelan machine in mid-December 2025, during the same period that Petróleos de Venezuela (PDVSA), Venezuela's state-owned oil company, publicly reported a cyberattack. Kaspersky described two batch scripts that coordinated execution through a NETLOGON share and launched a wiper that overwrote physical drive sectors, cleared volume journal records, exhausted storage, and recursively deleted files. The malware included target-specific logic, and independent reviewers cited by Zero Day identified a PDVSA.com domain value in the attack chain.
The linkage between Lotus Wiper and the December 2025 PDVSA incident remains unproven. Zero Day and The Record both noted that public evidence does not prove Lotus Wiper was the malware used in the PDVSA attack. The PDVSA incident itself had operational consequences: Bloomberg Línea reported in January 2026 that the company's SCADA platform, used for refinery processes, compression plants, and pipelines, was affected, along with SAP and production-data systems. Employees in several departments were reportedly relying on WhatsApp, Telegram, phone calls, and handwritten reports while internal systems remained unavailable.
Attribution remains disputed. Venezuelan officials blamed the United States, while public technical reporting has not tied Lotus Wiper or the PDVSA incident to a named US government unit or to a specific intrusion set. The source record supports a likely relationship between Lotus Wiper, Venezuela's energy sector, and PDVSA-specific targeting. It does not support treating the Lotus Wiper deployment against PDVSA as confirmed.
Impact
Bloomberg Línea reported disruption to PDVSA's SCADA platform for refinery processes, compression plants, and pipelines, plus SAP and production-data systems. Export operations were delayed and some oil cargo deliveries were temporarily affected according to contemporaneous reporting. Full recovery duration and financial impact were not publicly disclosed. Kaspersky found no ransom demand in the Lotus Wiper artifacts and assessed the malware as destructive rather than financially motivated.
Sources
- Kaspersky Securelist: https://securelist.com/tr/lotus-wiper/119472/ (English page served at Turkish-locale path)
- https://www.zetter-zeroday.com/hwiper-targeting-venezuelas-state-oil-company-discovered/
- https://www.bloomberglinea.com/latinoamerica/venezuela/la-venezolana-pdvsa-lleva-procesos-diarios-via-whatsapp-tras-ciberataque-de-diciembre/
- https://therecord.media/hackers-venezuela-wiper-malware-oil
- https://www.securityweek.com/new-wiper-malware-targeted-venezuelan-energy-sector-prior-to-us-intervention/