LazyWiper

MITRE
Malware Type:
Other
First seen:
Unknown
Last seen:
Unknown
Details:

[LazyWiper](https://attack.mitre.org/software/S9039) is a destructive malware observed targeting a manufacturing sector company during the [2025 Poland Wiper Attacks](https://attack.mitre.org/campaigns/C0063). [LazyWiper](https://attack.mitre.org/software/S9039) is a native Windows PowerShell script that is believed to have been generated by a large language model (LLM). [LazyWiper](https://attack.mitre.org/software/S9039) overwrites files on the system using the C# function `WriteRandomBytes()` and can targets multiple specific file types by their extensions.(Citation: CERT Polska)

Associated Techniques (8)
ID ATT&CK Tactics
T1059.001 PowerShell -
T1082 System Information Discovery -
T1083 File and Directory Discovery -
T1480 Execution Guardrails -
T1485 Data Destruction -
T1588.007 Artificial Intelligence -
T1679 Selective Exclusion -
T1685 Disable or Modify Tools -
Metadata
ID: 164721
Created: 28/04/2026 16:00
Updated: 09/05/2026 16:00