All techniques
EX-0010.02
ST0004Execution
sub-technique

Wiper Malware

Parent: EX-0010

Description

Wipers deliberately destroy or irreversibly corrupt data and, in some cases, executable images to impair or end mission operations. Destructive routines may overwrite with patterns or pseudorandom data, repeatedly reformat volumes, trigger wear mechanisms on non-volatile memory, or manipulate low-level translation layers so recovery tools see a blank or inconsistent device. Activation can be immediate or staged, sleeping until a specific time, pass, or maintenance action, and may be paired with anti-recovery steps such as erasing checksums, undo logs, or golden images. Because wipers operate at storage and image layers that underpin many subsystems, collateral effects can cascade: autonomy enters safing without viable recovery paths, downlinks carry only noise, and subsequent updates cannot be authenticated or applied. The defining feature is irreversible loss of data or executables as the primary objective, rather than concealment or monetization.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(f)
    addresses
    high
    derived

    Integrity protection of executable images and configuration resists wiper-driven destruction.

  • craAnnex I, Part I, (2)(h)
    addresses
    high
    derived

    Availability-after-incident obligation covers wiper events: products must maintain or recover essential functions even after destructive payloads execute.

  • craAnnex I, Part I, (2)(k)
    addresses
    moderate
    derived

    Exploitation-mitigation mechanisms (immutable storage, write-protected partitions) bound the destructive scope of wiper attacks.

  • craAnnex I, Part II, (3)
    addresses
    moderate
    direct

    Memory-tampering exploitation (primary mapping: Annex I, Part I, (2)(k)) requires regular tests under (3) — memory-protection mitigations need periodic validation through fuzzing and overflow testing.

  • eu-space-actArt. 86(1)
    addresses
    high
    direct

    Wiper malware destroys data and images; 86(1)'s backup management policy is the operator's primary recovery mechanism against destructive attacks.

  • eu-space-actArt. 87(2)
    addresses
    high
    direct

    87(2)'s response-and-recovery plans cover the post-wiper restoration discipline including identification of affected systems and image-restoration sequencing.

  • eu-space-actArt. 87(4)
    addresses
    moderate
    direct

    Wiper recovery (primary: Art. 87(2) BCDR) cascades to 87(4) — staff implementing image-restoration sequences need role-specific training under 87(4).

  • nis2Art. 21(2)(b)
    addresses
    high
    derived

    Wiper deployment is a destruction-class incident; Art. 21(2)(b)'s incident-handling capability must trigger fast detection (downlinks-as-noise, FDIR-into-safing patterns) and forensic preservation despite cascading subsystem effects.

  • nis2Art. 21(2)(c)
    addresses
    high
    direct

    Backup management, disaster recovery, and crisis management under Art. 21(2)(c) are the obligations that ensure mission continuity in the face of irreversible data/image destruction — including custody of golden images and undo logs the wiper attempts to erase.

  • nis2Art. 23(1)
    triggers obligation
    high
    direct

    Irreversible loss of data or executables on a spacecraft providing essential services causes severe operational disruption and meets Art. 23(3)(a); Art. 23(1) reporting (24h early warning, 72h notification) applies.

  • nis2Art. 23(2)
    addresses
    high
    derived

    Primary mapping to Art. 23(1) treats wiper malware as a significant incident triggering reporting. Art. 23(2) addresses the timing requirement (without undue delay after becoming aware), automatic on Art. 23(1).

  • nis2Art. 23(3)
    relates to
    moderate
    derived

    Primary mapping to Art. 23(1) treats wiper malware as significant. Art. 23(3) significance criteria are met directly: destructive wipes cause operational disruption and considerable damage; in space operations they often have cross-border impact when the operator's services span Member States.

  • nis2Art. 23(4)
    addresses
    moderate
    derived

    Primary mapping to Art. 23(1) triggers Art. 23(4) deadlines. Wiper events are time-critical and typically detected after data is already destroyed, so the 24-hour early warning often lands first with limited information.

  • nis2-implAnnex 3.3.1
    addresses
    moderate
    derived

    Wiper events leave operator-visible aftermath; Annex 3.3.1 mechanism is the upstream feeder that surfaces such suspicious events to assessment and incident-response procedures.

  • nis2-implAnnex 3.4.1
    addresses
    moderate
    derived

    Wiper events require immediate assessment to classify scope (data destroyed, executable images affected) and severity before Annex 3.5.1 response activates.

  • nis2-implAnnex 3.4.2
    addresses
    moderate
    derived

    Annex 3.4.2 operational assessment criteria apply to wiper events: scope of destruction, affected subsystems, and recovery feasibility drive the incident classification feeding 3.5.1.

  • nis2-implAnnex 3.5.1
    addresses
    moderate
    derived

    Incident-response procedures govern containment and recovery from wiper events under documented containment, eradication and recovery stages.

  • nis2-implAnnex 3.6.1
    addresses
    moderate
    derived

    Wiper events are the canonical class for which post-incident review is essential — the review identifies how destructive code reached production and how backup integrity held under attack.

  • nis2-implAnnex 3.6.2
    addresses
    moderate
    derived

    Post-incident review of a wiper event must contribute to improving the security approach — typically updating backup discipline, integrity-verification cadence and segmentation boundaries.

  • nis2-implAnnex 3.6.3
    addresses
    moderate
    derived

    Planned-interval review under Annex 3.6.3 must include wiper events in the population whose post-incident-review status is tracked.

  • nis2-implAnnex 4.2.1
    addresses
    high
    derived

    Backup obligations are the principal recovery lever for wiper events; without backups the destruction is final, with them the entity can restore mission-critical data and configuration.

  • nis2-implAnnex 4.2.3
    addresses
    high
    direct

    Regular integrity checks on backup copies are the procedural mechanism that detects backup-targeting wiper variants before they corrupt the recovery surface; this is the specific control the implementing regulation requires.

  • nis2-implAnnex 6.9.1
    addresses
    high
    derived

    Wiper malware is the canonical destructive-software class the malware-protection obligations are designed to counter through detection and prevention.

ENISA controls

  • Tested backups with verified integrity are the recovery path when wiper malware destroys data or executable images.

  • Restoration to gold images per the software-updates procedure is the canonical defense against wiper-induced executable-image destruction.

  • Incident Recovery Plan defines the wiper-recovery sequence (image restoration, golden-copy reload) including roles and responsibilities of stakeholders.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, EX-0010.02 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.