destructive malware wiper

Destructive 'Lotus' wiper attack hits PDVSA and the Venezuelan energy sector

On December 15, 2025, Petróleos de Venezuela (PDVSA) reported a cyberattack aimed at disrupting its operations, which affected its administrative systems and temporarily interrupted the delivery of oil shipments, forcing staff to resort to manual record-keeping. Kaspersky linked the incident to a previously unknown destructive malware dubbed “Lotus,” which deletes recovery mechanisms, overwrites physical disks, and deletes files, rendering the computers irrecoverable; samples were uploaded from Venezuela in mid-December and referenced pdvsa.com. PDVSA blamed the United States and “stateless actors,” an accusation that neither Washington confirmed nor security researchers supported with technical evidence.

Impact details

Public reports describe a cyberattack that has affected PDVSA’s administrative and export operations, and security coverage describes the activity of the “Lotus Wiper” program against Venezuelan companies in the energy sector. PDVSA stated that its operational areas and export commitments continued without interruption, while media reports indicated disruptions; public sources do not demonstrate that all of PDVSA’s affected systems were wiped.

administrative systemsenergy export operationsenergy service systemsPossible systems joined to a Windows domain

Classification & severity

Category
Malicious code
Subtype
destructive malware wiper
Confidence
High

A public affairs report links the disruption at PDVSA and in the energy sector to a cyberattack, while another security report describes the activity of the “Lotus Wiper” program against Venezuelan companies in the energy sector.

Severity assessment

High
Functional impact
Degraded (critical)
Information impact
Destructive loss
Affected scope
Sector
Critical service
Disrupted
Public confidence
Moderate
Recoverability
Extended

The incident affected critical systems in the energy sector, and public reports corroborate the activity of destructive malware within the same campaign. The exact extent of PDVSA’s data loss remains a subject of controversy among public sources.

Service disrupted IntegrityAvailability

Timeline

Other

According to Kaspersky, the destructive malware "Lotus" was compiled in late September 2025, suggesting months of preparation.

Disclosure

PDVSA publicly denounces a cyberattack aimed at disrupting its operations, which affected administrative systems, and blames the United States and “stateless actors.”

Compromise

Media reports and internal sources indicate disruptions in oil shipments, the use of manual records, and the isolation of facilities; Lotus wiper samples referencing pdvsa.com were uploaded from Venezuela in mid-December.

Publication

Kaspersky and specialized media outlets (The Record, BleepingComputer, Dark Reading) publish a technical analysis of the Lotus wiper deployed against Venezuela’s energy and utilities sector.

Evidence & sources

7 sources