ZeroCleare is a destructive Windows wiper associated with Iranian state-aligned operations and used against organizations in the Middle East, particularly energy and industrial environments. Public reporting has linked it to activity involving groups tracked as APT34/OilRig, MuddyWater-related ecosystems, Pumpkin Sandstorm, and later disruptive campaigns such as HomeLand Justice. It is part of a broader Iranian pattern of destructive malware that includes Shamoon, Dustman, Meteor, and Apostle.
The malware is designed to render systems inoperable by directly corrupting disk contents and file-system structures. ZeroCleare has been observed using the EldoS RawDisk driver to obtain low-level disk access and overwrite critical disk areas, including the master boot record and partitions. Variants have also accepted operator-supplied command-line arguments to select drives for destruction rather than limiting wiping to the system drive. This operator-driven behavior indicates controlled deployment during targeted intrusions rather than indiscriminate self-propagation.
A notable feature of ZeroCleare is its use of vulnerable signed drivers to bypass Windows Driver Signature Enforcement and load the unsigned RawDisk component. Reporting has specifically described abuse of a signed VirtualBox driver for this purpose, making bring-your-own-vulnerable-driver tradecraft central to its execution chain. ZeroCleare has also been associated with malicious PowerShell used to bypass Windows protections and facilitate execution.
ZeroCleare is best understood as a purpose-built sabotage tool rather than ransomware or espionage malware. Its operational role is destructive impact: wiping disks, corrupting file systems, and disrupting business operations. It has been deployed in campaigns targeting energy companies and other regional entities in the Arabian Peninsula and Middle East, and later appeared in politically motivated disruptive operations. Its tradecraft reflects a continuation of Iranian destructive malware development that combines legitimate or signed driver abuse with direct disk overwriting to maximize damage on Windows hosts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In 2019-2020, a couple new wipers – ZeroCleare and Dustman, were exposed in 2 operations against entities in the Arabian Peninsula.
In 2019-2020, a couple new wipers – ZeroCleare and Dustman, were exposed in 2 operations against entities in the Arabian Peninsula.
During HomeLand Justice, threat actors used a version of ZeroCleare to wipe disk drives on targeted hosts.
...ROADSWEEP, the CHIMNEYSWEEP backdoor, and a ZEROCLEAR wiper variant (aka Cl Wiper)...
17 distinct techniques documented for this family, organized by ATT&CK tactic.
APT19 downloaded and launched code within a SCT file; APT32 used COM scriptlets to download Cobalt Strike beacons; APT37 used Ruby scripts to execute payloads; ArcaneDoor included the adversary executing command line interface (CLI) commands.
The content repeatedly describes threat actors and malware using PowerShell scripts/commands for execution, download, staging, reconnaissance, persistence, credential access, lateral movement, and defense evasion; e.g., "Sandworm Team used PowerShell scripts to run a credential harvesting tool in memory to evade defenses."
During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.
VOID MANTICORE has masqueraded malicious payloads to resemble legitimate applications. During HomeLand Justice, threat actors renamed ROADSWEEP to GoXML.exe and ZeroCleare to cl.exe.
The content repeatedly describes threat actors and malware using valid, stolen, forged, self-signed, or abused code-signing certificates to sign malware and appear legitimate, including examples such as AppleJeus using a valid digital signature from Sectigo, APT41 leveraging code-signing certificates, FIN7 signing Carbanak payloads, and SUNBURST being digitally signed by SolarWinds.
wiper malware can be defined as malicious software that tries to destroy data.
Many wipers also make sure to overwrite the Master Boot Record (MBR) of the disk.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
26 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Destructive wiper used to wipe disk drives on targeted hosts; in this activity it was renamed to cl.exe.
A destructive wiper used heavily against energy and industrial targets, relying on modified legitimate drivers to damage systems.
An Iran-linked wiper malware family cited as part of a broader arsenal developed to destroy data and disrupt operations at scale.
Destructive wiper malware previously deployed by Iranian operators against organizations in the Middle East.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.