Description
ZeroCleare is a destructive data wiper that hit energy and government organizations in the Middle East in 2019, which researchers attributed to Iranian state sponsored actors. It overwrote the master boot record and system files on infected Windows systems to destroy data and disrupt operations rather than to demand ransom.
Stats
- First seen
- March 2022
- Last seen
- September 2026
Also known as
Zerocleare
MITRE ATT&CK techniques
8 techniques across 6 tactics.
Associated groups
Associated campaigns
Alert name variants
| Alert Name |
|---|
| Win32.Trojan.ZeroCleare |
| Win64.Trojan.Zerocleare |
| Win64.Trojan.ZeroCleare |