ZeroCleare — Malware Profile
ZeroCleare is a wiper malware that has been used in conjunction with the RawDisk driver since at least 2019 by suspected Iran-nexus threat actors including activity targeting the energy and industrial sectors in the Middle East and political targets in Albania.
MITRE ATT&CK techniques (8)
- T1059 Command and Scripting Interpreter
- T1059.001 PowerShell
- T1068 Exploitation for Privilege Escalation
- T1070.004 File Deletion
- T1106 Native API
- T1553.002 Code Signing
- T1561.002 Disk Structure Wipe
- T1680 Local Storage Discovery