WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts Wiper Malware Impacting More Organizations Across the World and Other Findings from Fortinet’s Latest Threat Report
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Wiper Malware Impacting More Organizations Across the World and Other Findings from Fortinet’s Latest Threat Report

Author: Alec Davison

Created: Thursday, February 23, 2023 - 18:27

Categories: Cybersecurity, Research

In the second half of 2022, security researchers at Fortinet observed destructive wiper malware attacks impacting more organizations around the world, as well as cybercriminals retooling existing botnets and reusing code to power more sophisticated attacks.

Fortinet’s just published study, 2H 2022 Threat Landscape Report, examines the cyber-threat landscape over last year’s second half to identify trends and offer insights on what network defenders should know to effectively protect their organizations in 2023. In the first half of 2022, there was a resurgence in wiper malware, mostly tied to the Russian invasion of Ukraine, but in the second half of 2022 wiper malware expanded into other countries, driving a 53 percent increase in wiper activity from Q3 to Q4. Although Fortinet initially observed wiper malware being developed and deployed by nation-state actors and targeted to countries involved in the Russian-Ukraine War, researchers are now seeing wipers being scaled and deployed worldwide. “These new strains are increasingly being picked up by cybercriminal groups and… Cybercriminals are also now developing their own wiper malware which is being used readily across [Cybercrime-as-a-Service (CaaS)] organizations, meaning that the threat of wiper malware is more widespread than ever and all organizations are a potential target.”

Fortinent also found threat actors are increasingly reusing old botnet and malware code  to launch attack campaigns more cost effectively. These included IoT botnet Mirai, remote access Trojan Gh0st RAT, and the infamous Emotet malware. Ransomware also continues to pose a significant threat, primarily due to the proliferation of Ransomware-as-a-Service (RaaS). The report found in the second half of 2022, the top five ransomware families accounted for roughly 37 percent of all ransomware attacks. Access the full report at Fortinet.

Related Resources

(TLP:CLEAR) Vulnerability Notification – Critical Vulnerability in Fortinet EMS Actively Exploited, CVE-2026-35616

May 29, 2026 in Cybersecurity, Security Preparedness

(TLP:CLEAR) GAO Report: Actions Needed to Address Persistent Cybersecurity Threats to the Water and Wastewater Sector

May 28, 2026 in Cybersecurity, Federal & State Resources, OT-ICS Security

(TLP:CLEAR) FBI Releases Multiple Alerts on Credential Theft and Evolving Ransomware Intrusion Techniques

May 28, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar