Meteor is a configurable Windows wiper used in the MeteorExpress operation that disrupted Iran’s railway system on July 9, 2021. Its primary purpose is destructive file wiping and disruption of system availability. It uses an encrypted JSON configuration to determine which locations to traverse and wipe, enabling its destructive behavior to be adapted to different environments.
Meteor can delete Volume Shadow Copies, disable recovery mode, alter boot configuration, and remove compromised machines from their domain to hinder restoration. Additional capabilities include changing local user passwords, logging off sessions, terminating selected processes, disabling network adapters through PowerShell, executing commands, creating scheduled tasks, and changing desktop wallpaper and lock-screen images. It can hide its console window, search for Kaspersky Antivirus, attempt to uninstall that product or remove its license, add attack-related files and folders to Microsoft Defender exclusions, and clear Windows event logs.
In the railway attack, operators abused Group Policy to distribute the toolkit within the compromised network. Batch scripts and compressed archives orchestrated deployment, and a scheduled task launched the wiper at a predetermined time. Meteor operated alongside a separate screen-locking component and scripts that impaired boot and recovery functionality. The operation targeted transportation infrastructure; its initial access vector and attribution to a known threat group were not established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Shamoon 4.0 and Meteor are the primary destructive payloads assessed as active in the current conflict cycle.
"...including the 2021 railway system disruption using the Meteor wiper..."
22 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware using PowerShell to execute payloads, run commands, download additional malware, perform lateral movement, evade defenses, and execute scripts in memory. | Examples include: 'APT28 downloads and executes PowerShell scripts and performs PowerShell commands'; 'APT3 has used PowerShell on victim systems to download and run payloads after exploitation'; 'TA505 has used PowerShell to download and execute malware and reconnaissance scripts.'
In order to disable the machine’s ability to boot up, bcd.bat creates an alternative boot.ini file that points the bootloader to impossibly high disk and partition numbers (10000000) and overwrites the system’s copy of boot.ini. The script then uses the native bcdedit command to list boot option identifiers and deletes each.
In order to disable the machine’s ability to boot up, bcd.bat creates an alternative boot.ini file that points the bootloader to impossibly high disk and partition numbers (10000000) and overwrites the system’s copy of boot.ini. The script then uses the native bcdedit command to list boot option identifiers and deletes each.
Agent Tesla has used ProcessWindowStyle.Hidden to hide windows. APT-C-36 has set the ShowWindow property of the Win32_ProcessStartup object to zero to hide PowerShell execution. APT19 used -W Hidden to conceal PowerShell windows by setting the WindowStyle parameter to hidden.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, enumerating PIDs, checking for specific process names, or using APIs such as CreateToolhelp32Snapshot and commands such as tasklist and ps.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
“It can: change passwords for all users; disable screensavers; terminate processes based on a list of target processes; install a screenlocker...”
“It also makes sure to delete shadow copies and removes the machine from the domain to avoid means of quick remediation.” | “It can: change passwords for all users; disable screensavers; terminate processes based on a list of target processes; install a screenlocker; disable recovery mode...”
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
36 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A destructive payload assessed as active in the current conflict cycle.
Destructive malware that hides its console window during execution to reduce visibility.
An Iran-linked wiper malware family referenced as part of a deliberate arsenal intended for destructive attacks and operational disruption.
Destructive wiper malware family referenced as part of Iran-aligned wiper tooling.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.