ZeroCleare
ZeroCleare is a destructive Windows wiper associated with Iranian state-aligned activity. The content links it to APT34/OilRig and to Microsoft-tracked Iranian activity including Pumpkin Sandstorm/DEV-0146, and notes its use during the HomeLand Justice attacks against the Government of Albania in 2022. It has been reported targeting industrial and energy environments in the Middle East, including energy sector targets in Saudi Arabia, and is described as being deployed heavily against energy and industrial sectors.
Its core purpose is destructive impact: ZeroCleare can corrupt the file system, wipe the system drive, and wipe disk drives on targeted hosts. The content specifically notes behavior consistent with low-level disk destruction, including use of the RawDisk driver to corrupt the file system and references to wiping disk structures such as the MBR/system drive.
Operationally, ZeroCleare can receive command-line arguments from an operator to trigger file-system corruption using the RawDisk driver. It can use a malicious PowerShell script to bypass Windows controls. It also abuses vulnerable signed drivers to bypass operating system safeguards and Microsoft Driver Signature Enforcement (DSE), after which it loads the unsigned RawDisk driver. The content specifically mentions abuse of vulnerable signed VBoxDrv and RawDisk-related drivers for this purpose.
In the Albania/HomeLand Justice reporting, actors deployed a version of ZeroCleare after ransomware activity, using a disk wiper tool (cl.exe) together with the raw disk driver rwdsk.sys. The advisory cited in the content states that cl.exe installs rwdsk.sys as a service named RawDisk3 and supports commands for installation, uninstallation, and wiping. Reported host-based indicators from that activity include MD5 hashes for cl.exe (7b71764236f244ae971742ee1bc6b098) and rwdsk.sys (8f6e7653807ebb57ecc549cef991d505).
The content also places ZeroCleare within a broader Iranian wiper arsenal alongside Shamoon, Dustman, Meteor, and Apostle, and notes that Dustman is related to ZeroCleare. High-confidence targeting references in the content are the Middle East, especially industrial and energy-sector organizations, and the Albanian government during HomeLand Justice.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
During HomeLand Justice, threat actors used a version of ZeroCleare to wipe disk drives on targeted hosts.
...ROADSWEEP, the CHIMNEYSWEEP backdoor, and a ZEROCLEAR wiper variant (aka Cl Wiper)...
“...it can also be used as a platform for spreading and activating destructive malware such as ZeroCleare and Dustman, tied to APT34.”
Techniques & procedures
16 distinct techniques documented for this family, organized by ATT&CK tactic.
Execution
4 techniques
Execution
APT19 downloaded and launched code within a SCT file; APT32 used COM scriptlets to download Cobalt Strike beacons; APT37 used Ruby scripts to execute payloads; ArcaneDoor included the adversary executing command line interface (CLI) commands.
The content repeatedly describes threat actors and malware using PowerShell scripts/commands for execution, download, staging, reconnaissance, persistence, credential access, lateral movement, and defense evasion; e.g., "Sandworm Team used PowerShell scripts to run a credential harvesting tool in memory to evade defenses."
Privilege Escalation
1 technique
Privilege Escalation
Medusa Group has utilized vulnerable or signed drivers to kill or delete services associated with endpoint detection and response (EDR) tools. ZeroCleare can deploy a vulnerable, signed driver on a compromised host to bypass operating system safeguards.
Stealth
4 techniques
Stealth
During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.
VOID MANTICORE has masqueraded malicious payloads to resemble legitimate applications. During HomeLand Justice, threat actors renamed ROADSWEEP to GoXML.exe and ZeroCleare to cl.exe.
Defense Impairment
1 technique
Defense Impairment
The content repeatedly describes threat actors and malware using valid, stolen, forged, self-signed, or abused code-signing certificates to sign malware and appear legitimate, including examples such as AppleJeus using a valid digital signature from Sectigo, APT41 leveraging code-signing certificates, FIN7 signing Carbanak payloads, and SUNBURST being digitally signed by SolarWinds.
Impact
4 techniques
Impact
Instead, they opted for rapid, recursive file-level destruction, overwriting targeted files with 4096-byte blocks of random data.
“AcidPour can identify various system locations and mapped devices on Linux systems as a precursor to wiping activity.”
APT37 has access to destructive malware that is capable of overwriting a machine's Master Boot Record (MBR). APT38 has used a custom MBR wiper named BOOTWRECK to render systems inoperable. CaddyWiper has the ability to destroy information about a physical drive's partitions including the MBR, GPT, and partition entries.
Recent activity
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Destructive wiper used to wipe disk drives on targeted hosts; in this activity it was renamed to cl.exe.
A destructive wiper used heavily against energy and industrial targets, relying on modified legitimate drivers to damage systems.
An Iran-linked wiper malware family cited as part of a broader arsenal developed to destroy data and disrupt operations at scale.
Destructive wiper malware previously deployed by Iranian operators against organizations in the Middle East.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.