Zerocleare

Malware updated 5 months ago (2024-05-20T11:17:29.978Z)
Download STIX
Preview STIX
ZeroCleare is a type of malware, specifically a wiper, known for its destructive capabilities. It targets computer systems and networks, rendering them unusable by deleting critical files and data. This malicious software has been linked to several actors associated with Iran's Ministry of Intelligence and Security (MOIS), as evidenced by the license key used in the wiper being identical to the one utilized in ZeroCleare. The malware gained notoriety when it was reportedly used in an attack on Bapco, a Bahraini national oil company, in late December 2019. This variant of ZeroCleare, known as Dustman, caused significant disruption. A comparative analysis of two waves of cyberattacks against Albanian government organizations reveals the use of both ROADSWEEP ransomware and ZEROCLEARE wiper. These attacks demonstrated a shift in tactics from previous Iranian-associated IT disruptive activities, which primarily involved the use of Disttrack-like malware variants weaponizing the ElodS RawDisk driver. In the case of the Albanian attacks, when network defenders identified and started responding to the ransomware activity, the cyber actors deployed a version of ZeroCleare destructive malware, indicating a layered approach to their offensive strategy. Historically, in the ZeroCleare and Dustman incidents of 2019, the wiper malware and raw disk drivers were unsigned, meaning they couldn't directly access the raw disk for quick data wiping. However, APT 34, an Iranian-linked threat actor also known as Oilrig, introduced a new method of attack by using a novel wiper malware called ZeroCleare to target oil companies in the Middle East. This evolution in tactics underscores the escalating sophistication of these threat actors and underscores the need for robust cybersecurity measures.
Description last updated: 2024-05-20T11:17:07.310Z
What's your take? (Question 1 of 3)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
Dustman is a possible alias for Zerocleare. Dustman is a destructive malware variant, specifically a wiper, that was first identified in late December 2019. This new strain of malware was discovered following incidents involving similar wipers such as ZEROCLEARE. Historically, these types of malware and their raw disk drivers were unsigned, m
2
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Wiper
Malware
Ransomware
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.