Malware designed to destroy or render data irrecoverable, with no intent of ransom, often for sabotage or geopolitical ends.
A wiper is a type of malware whose purpose is not financial gain but destruction. Unlike ransomware, which encrypts data to release it against payment, the wiper irreversibly destroys or corrupts files and sometimes the systems themselves, with no prospect of recovery. Its logic is that of sabotage, and it is frequently associated with geopolitical motives or conflicts, deployed to paralyze adversaries' infrastructure. Some wipers disguise themselves as ransomware to blur attribution and sow confusion, displaying a sham ransom demand while the data are already destroyed. The emblematic example remains NotPetya in 2017, which, under the guise of ransomware, wiped the data of countless companies worldwide and caused billions of dollars in damage. For insurance, the wiper concentrates several major difficulties, namely the catastrophic scale of the damage, the impossibility of recovery which aggravates business interruption, and above all the question of state attribution, which can trigger war exclusion clauses and has fueled the debate on silent cyber.
A global logistics company sees, in a matter of minutes, all of its systems wiped by malware spread through a booby-trapped software update. Rebuilding takes weeks, and the insurer invokes a possible state attribution to dispute the application of the war exclusion.
wiper, logiciel d'effacement, maliciel destructeur