Power Grid
Venezuelan energy and utilities sector — Lotus Wiper destructive campaign
Late 2025–early 2026; disclosed 21 April 2026
Venezuela (victim company undisclosed; country-level marker)
What happened
Kaspersky identified artifacts from a highly targeted destructive campaign against an unnamed Venezuelan energy or utilities company. Two preparatory scripts disabled defences, changed or disabled accounts, cut network interfaces and coordinated execution before launching a previously undocumented payload named Lotus Wiper. The wiper removed recovery mechanisms, overwrote physical drives and systematically deleted files, leaving affected systems unrecoverable. The samples lacked payment instructions or extortion mechanisms, supporting a destructive rather than financial motive. Kaspersky did not publicly identify the victim or attacker, quantify the operational impact, or establish a connection to PDVSA's December administrative-system incident, so this remains a separate country-level record.
When cited sources give different casualty, damage or spill figures for this event, they’re reported side by side above rather than merged into one number. See how confidence levels work.
- Evidence
- Documented
- Confidence
- High
- Infrastructure
- Power Grid
- Latitude
- 6.4200°
- Longitude
- -66.5900°
Attribution
Responsibility has not been established in the cited reporting.
