Meteor is a Windows destructive malware family classified as a wiper. It was publicly identified in connection with the July 2021 disruption of Iran’s railway system, where it formed part of a multi-component attack chain that combined filesystem destruction, system lockout, and likely boot-record corruption. The operation has been referred to as MeteorExpress, and public reporting has not conclusively tied it to a previously known threat group. Assessments have described the operators as an unfamiliar or newly observed actor with prior knowledge of the victim environment and tooling designed for reuse.
Meteor is externally configurable and executes destructive actions based on an encrypted configuration. Its core role is wiping files across configured paths, while companion components in the broader toolkit were used to lock systems and reportedly corrupt boot structures. The malware and associated scripts also impair recovery by deleting shadow copies, altering boot and recovery settings, clearing event logs, and disconnecting affected systems from the network or domain to slow remediation. Additional defense-evasion behavior includes checking for security software, attempting to uninstall or weaken antivirus protections, and adding exclusions to Microsoft Defender. Meteor can also hide its console window during execution.
Observed execution in the railway attack involved scheduled-task-based launch and orchestration through batch scripts, with distribution inside the victim environment via Group Policy and archived payload bundles. Public reporting also notes broader built-in capabilities beyond those used in the initial incident, including terminating selected processes, changing user passwords, logging off sessions, creating scheduled tasks, disabling screensavers, executing commands, and changing desktop wallpaper and lock-screen images. Taken together, Meteor represents a reusable destructive toolkit aimed at maximizing operational disruption on Windows systems while hindering recovery and forensic visibility.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Shamoon 4.0 and Meteor are the primary destructive payloads assessed as active in the current conflict cycle.
"...including the 2021 railway system disruption using the Meteor wiper..."
26 distinct techniques documented for this family, organized by ATT&CK tactic.
Meteor will attempt to remove the machine from the domain via WinApi functions. If that fails it will then attempt to do the same via an equivalent WMI command.
“One is the main payload, the Meteor wiper, which comes in the form of an executable dropped under env.exe or msapp.exe,and is executed as a scheduled task with a single argument–an encrypted JSON configuration file, msconf.conf...”
The content repeatedly describes threat actors and malware using PowerShell to execute payloads, run commands, download additional malware, perform lateral movement, evade defenses, and execute scripts in memory. | Examples include: 'APT28 downloads and executes PowerShell scripts and performs PowerShell commands'; 'APT3 has used PowerShell on victim systems to download and run payloads after exploitation'; 'TA505 has used PowerShell to download and execute malware and reconnaissance scripts.'
APT1 has used the Windows command shell to execute commands, and batch scripting to automate execution. Blue Mockingbird has used batch script files to automate execution and deployment of payloads. During HomeLand Justice, threat actors used Windows batch files for persistence and execution.
“One is the main payload, the Meteor wiper, which comes in the form of an executable dropped under env.exe or msapp.exe,and is executed as a scheduled task with a single argument–an encrypted JSON configuration file, msconf.conf...”
“It can: change passwords for all users; disable screensavers; terminate processes based on a list of target processes; install a screenlocker; disable recovery mode...”
In order to disable the machine’s ability to boot up, bcd.bat creates an alternative boot.ini file that points the bootloader to impossibly high disk and partition numbers (10000000) and overwrites the system’s copy of boot.ini. The script then uses the native bcdedit command to list boot option identifiers and deletes each.
“One is the main payload, the Meteor wiper, which comes in the form of an executable dropped under env.exe or msapp.exe,and is executed as a scheduled task with a single argument–an encrypted JSON configuration file, msconf.conf...”
“It can: change passwords for all users; disable screensavers; terminate processes based on a list of target processes; install a screenlocker; disable recovery mode...”
“It also makes sure to delete shadow copies and removes the machine from the domain to avoid means of quick remediation.”
The attackers abused Group Policy to distribute a cab file to conduct their attack.
It also makes sure to delete shadow copies and removes the machine from the domain to avoid means of quick remediation.
In order to disable the machine’s ability to boot up, bcd.bat creates an alternative boot.ini file that points the bootloader to impossibly high disk and partition numbers (10000000) and overwrites the system’s copy of boot.ini. The script then uses the native bcdedit command to list boot option identifiers and deletes each.
The attackers then use the native wevtutil command to clear Security, System, and Application event logs.
The content repeatedly describes threat actors and malware deleting files, tools, scripts, logs, droppers, staged data, and artifacts from compromised systems to cover tracks, remove evidence, or self-delete.
Several entries describe malware examining running processes to determine if a debugger, sandbox, virtual environment, or analysis/security tools are present, such as AsyncRAT checking for a debugger, RogueRobin enumerating Wireshark and Sysinternals processes, and P8RAT checking for processes associated with virtual environments.
Agent Tesla has used ProcessWindowStyle.Hidden to hide windows. APT-C-36 has set the ShowWindow property of the Win32_ProcessStartup object to zero to hide PowerShell execution. APT19 used -W Hidden to conceal PowerShell windows by setting the WindowStyle parameter to hidden.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, enumerating PIDs, checking for specific process names, or using APIs such as CreateToolhelp32Snapshot and commands such as tasklist and ps.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
Several entries describe malware examining running processes to determine if a debugger, sandbox, virtual environment, or analysis/security tools are present, such as AsyncRAT checking for a debugger, RogueRobin enumerating Wireshark and Sysinternals processes, and P8RAT checking for processes associated with virtual environments.
“At its most basic functionality, the Meteor wiper takes a set of paths from the encrypted config and walks these paths, wiping files,” Guerrero-Saade wrote.
“It can: change passwords for all users; disable screensavers; terminate processes based on a list of target processes; install a screenlocker...”
“It also makes sure to delete shadow copies and removes the machine from the domain to avoid means of quick remediation.” | “It can: change passwords for all users; disable screensavers; terminate processes based on a list of target processes; install a screenlocker; disable recovery mode...”
cache.bat performs three main functions. First, it will disconnect the infected device from the network.
"Play has used Base64-encoded PowerShell scripts to disable Microsoft Defender," "StrongPity can use PowerShell to add files to the Windows Defender exclusions list," and "ZeroCleare can use a malicious PowerShell script to bypass Windows controls."
Then it checks to see if Kaspersky antivirus is installed on the machine, in which case it’ll exit. Finally, cache.bat will create Windows Defender exclusions for all of its components, effectively clearing the way for a successful infection without impediments.
BlackByte Ransomware 'adds .JS and .EXE extensions to the Microsoft Defender exclusion list'; PureCrypter 'executed Set-MpPreference -ExclusionPath'; QakBot 'modify the Registry to add its binaries to the Windows Defender exclusion list'; Raspberry Robin 'add an exception to Microsoft Defender that excludes the entire main drive'; StrongPity 'add directories used by the malware to the Windows Defender exclusions list'; XLoader 'can add the path of its executable to the Microsoft Defender exclusion list'; ZIPLINE 'can add itself to the exclusion list for the Ivanti Connect Secure Integrity Checker Tool.'
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
35 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A destructive payload assessed as active in the current conflict cycle.
Destructive malware that hides its console window during execution to reduce visibility.
An Iran-linked wiper malware family referenced as part of a deliberate arsenal intended for destructive attacks and operational disruption.
Destructive wiper malware family referenced as part of Iran-aligned wiper tooling.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.