LazyWiper
S9039 · Windows
LazyWiper is a destructive malware observed targeting a manufacturing sector company during the 2025 Poland Wiper Attacks. LazyWiper is a native Windows PowerShell script that is believed to have been generated by a large language model (LLM). LazyWiper overwrites files on the system using the C# function WriteRandomBytes() and can target multiple specific file types by their extensions.
ATT&CK S9039
Sigma rules0
YARA rules0
Live IOCs0