Destructive 'Lotus' wiper attack hits PDVSA and the Venezuelan energy sector
On December 15, 2025, Petróleos de Venezuela (PDVSA) reported a cyberattack aimed at disrupting its operations, which affected its administrative systems and temporarily interrupted the delivery of oil shipments, forcing staff to resort to manual record-keeping. Kaspersky linked the incident to a previously unknown destructive malware dubbed “Lotus,” which deletes recovery mechanisms, overwrites physical disks, and deletes files, rendering the computers irrecoverable; samples were uploaded from Venezuela in mid-December and referenced pdvsa.com. PDVSA blamed the United States and “stateless actors,” an accusation that neither Washington confirmed nor security researchers supported with technical evidence.
Impact details
Public reports describe a cyberattack that has affected PDVSA’s administrative and export operations, and security coverage describes the activity of the “Lotus Wiper” program against Venezuelan companies in the energy sector. PDVSA stated that its operational areas and export commitments continued without interruption, while media reports indicated disruptions; public sources do not demonstrate that all of PDVSA’s affected systems were wiped.
Classification & severity
- Category
- Malicious code
- Subtype
- destructive malware wiper
- Confidence
- High
A public affairs report links the disruption at PDVSA and in the energy sector to a cyberattack, while another security report describes the activity of the “Lotus Wiper” program against Venezuelan companies in the energy sector.
Severity assessment
High- Functional impact
- Degraded (critical)
- Information impact
- Destructive loss
- Affected scope
- Sector
- Critical service
- Disrupted
- Public confidence
- Moderate
- Recoverability
- Extended
The incident affected critical systems in the energy sector, and public reports corroborate the activity of destructive malware within the same campaign. The exact extent of PDVSA’s data loss remains a subject of controversy among public sources.
Timeline
According to Kaspersky, the destructive malware "Lotus" was compiled in late September 2025, suggesting months of preparation.
PDVSA publicly denounces a cyberattack aimed at disrupting its operations, which affected administrative systems, and blames the United States and “stateless actors.”
Media reports and internal sources indicate disruptions in oil shipments, the use of manual records, and the isolation of facilities; Lotus wiper samples referencing pdvsa.com were uploaded from Venezuela in mid-December.
Kaspersky and specialized media outlets (The Record, BleepingComputer, Dark Reading) publish a technical analysis of the Lotus wiper deployed against Venezuela’s energy and utilities sector.