:

NEW LOTUS MALWARE TARGETS VENEZUELAN ENERGY FIRMS

AI DESK1 MIN READ
TUE, APR 21, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

A previously unknown data-wiping malware called Lotus was deployed in targeted attacks against Venezuelan energy and utility organizations last year. The discovery reveals a coordinated campaign against critical infrastructure.

Security researchers identified the Lotus malware through analysis of intrusions affecting multiple Venezuelan energy and utilities firms. The wiper was designed to destroy data on compromised systems, a tactic commonly associated with destructive cyberattacks against critical infrastructure. The attacks underscore growing threats to Latin American energy sectors. Venezuelan utilities face significant cyber risks given the country's geopolitical position and existing infrastructure vulnerabilities. Lotus shares characteristics with other data-wiping malware families but operates as a distinct threat. Researchers have not yet attributed the attacks to a specific threat actor, though the targeting pattern suggests organized coordination. Energy organizations are advised to review access logs for suspicious activity, implement robust backup strategies independent of primary networks, and monitor for indicators of compromise associated with the malware. The discovery adds to a growing catalog of destructive malware targeting utilities globally.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

A security researcher has identified a method for untrusted websites to freeze macOS systems, dubbed "The Deathray." The technique exploits browser behavior to render machines unresponsive.

3H AGODev Desk

Hardware wallet maker Trezor confirmed a data breach affecting its email provider, exposing hundreds of thousands of crypto owners to targeted scams. This marks the second breach involving a third-party service that Trezor depends on.

3H AGOAI Desk

A US judge dismissed two lawsuits against LinkedIn for scanning users' browser extensions, ruling that downloading extensions constitutes voluntary data exposure. The Microsoft subsidiary prevailed on its motion to dismiss.

4H AGOAI Desk

Florida's Department of Highway Safety and Motor Vehicles confirmed a breach of its DAVID driver database after attackers exploited stolen credentials from a police department employee.

5H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.