Netskope Threat Labs

ZeroCleare

ATP Sandbox Adv. HeuristicsNetskope IPS

ZeroCleare is a destructive data wiper that hit energy and government organizations in the Middle East in 2019, which researchers attributed to Iranian state sponsored actors. It overwrote the master boot record and system files on infected Windows systems to destroy data and disrupt operations rather than to demand ransom.

First seen
March 2022
Last seen
September 2026
Zerocleare

8 techniques across 6 tactics.

TA0002 Execution

TA0004 Privilege Escalation

  • T1068Exploitation for Privilege Escalation

TA0005 Stealth

TA0007 Discovery

  • T1680Local Storage Discovery

TA0040 Impact

TA0112 Defense Impairment

Alert Name
Win32.Trojan.ZeroCleare
Win64.Trojan.Zerocleare
Win64.Trojan.ZeroCleare