[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fe_LigkSBB3a2ONSzCiT6jAP9G6oq47LU3FyVvjTSZik":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":18,"created_at":19,"published_at":20,"article":21,"tags":25,"podcasts":38},"b7f4bc8f-5c63-4629-8038-fb20156c8411","state-sponsored-wiper-attack-devastates-venezuelan-energy-infrastructure","ba284c95-a0f4-4984-9a7a-eb10792c43ca","State-Sponsored Wiper Attack Devastates Venezuelan Energy Infrastructure","The Lotus Wiper attack demonstrates how sophisticated threat actors can systematically destroy critical infrastructure by first disabling security defenses and establishing persistent network execution capabilities. The malware's ability to progress from initial compromise to complete data destruction shows inadequate incident response capabilities and insufficient network isolation of critical energy systems. This geopolitically-motivated attack highlights how nation-state actors target essential services during periods of political tension, making robust cyber defense essential for national security.","**Immediate actions:**\n- Implement network segmentation to isolate critical energy control systems from corporate networks\n- Deploy endpoint detection and response (EDR) solutions with behavioral analysis to detect wiper malware\n- Establish automated backup systems with offline storage for critical operational data\n\n**Long-term improvements:**\n- Develop incident response playbooks specifically for destructive malware targeting critical infrastructure\n- Create redundant communication channels and manual override procedures for essential systems\n- Implement application whitelisting on all critical operational technology (OT) systems\n\n**Detection measures:**\n- Monitor for suspicious batch script execution and defense evasion activities\n- Establish baseline monitoring for unusual file deletion patterns and drive overwrite operations",[12,13,14,15,16,17],"NIST IR-4","CIS Control 12","CIS Control 11","NIST PR.AC-5","IEC 62443","NERC CIP-005","published","2026-04-23T08:10:00.757237+00:00","2026-04-23T08:10:00.634+00:00",{"id":7,"url":22,"slug":23,"title":24},"https:\u002F\u002Fwww.securityweek.com\u002Fnew-wiper-malware-targeted-venezuelan-energy-sector-prior-to-us-intervention\u002F","new-wiper-malware-targeted-venezuelan-energy-sector-prior-to-us-intervention-36718b","New Wiper Malware Targeted Venezuelan Energy Sector Prior to US Intervention",[26,32],{"id":27,"name":28,"slug":29,"description":30,"color":31},"182e11d5-57c4-444e-8ec8-4682ad60261b","Incident Response","incident-response","Slow detection, poor containment, missing playbooks","#14b8a6",{"id":33,"name":34,"slug":35,"description":36,"color":37},"f43a7f30-5046-4b10-9dba-1a704139821e","Network Segmentation","network-segmentation","Lateral movement, flat networks, missing firewalls","#06b6d4",[39],{"id":40,"date":41,"edition":42,"title":43,"audio_url":44},"13803bfe-35d0-4393-8bb2-a40492bb7ef5","2026-04-22","afternoon","ThreatNoir Afternoon Brief — April 22","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-04-22\u002Fthreatnoir-afternoon-brief-2026-04-22.mp3"]