Incident responders analyzing attacks on several energy sector companies concluded that malware initially reported as ransomware was in fact a destructive wiper with no functional recovery mechanism.
The malware displayed a ransom note and demanded payment, but analysis showed encryption keys were never retained — files were irrecoverably corrupted regardless of any payment.
The disguise appears intended to delay attribution and muddy response efforts. Researchers note the tactic mirrors previous destructive campaigns attributed to state-aligned actors during geopolitical tensions.
Energy operators are being urged to test offline backup restoration, segment operational networks and treat any ransomware event in critical infrastructure as potentially destructive.
