Power Grid

Venezuelan energy and utilities sector — Lotus Wiper destructive campaign

Late 2025–early 2026; disclosed 21 April 2026

Venezuela (victim company undisclosed; country-level marker)

What happened

Kaspersky identified artifacts from a highly targeted destructive campaign against an unnamed Venezuelan energy or utilities company. Two preparatory scripts disabled defences, changed or disabled accounts, cut network interfaces and coordinated execution before launching a previously undocumented payload named Lotus Wiper. The wiper removed recovery mechanisms, overwrote physical drives and systematically deleted files, leaving affected systems unrecoverable. The samples lacked payment instructions or extortion mechanisms, supporting a destructive rather than financial motive. Kaspersky did not publicly identify the victim or attacker, quantify the operational impact, or establish a connection to PDVSA's December administrative-system incident, so this remains a separate country-level record.

When cited sources give different casualty, damage or spill figures for this event, they’re reported side by side above rather than merged into one number. See how confidence levels work.

Evidence
Documented
Confidence
High
Infrastructure
Power Grid
Latitude
6.4200°
Longitude
-66.5900°

Attribution

Responsibility has not been established in the cited reporting.

Sources

  1. Lotus Wiper — a new threat to the energy and utilities sectorKaspersky Global Research and Analysis Team · Incident reporting