Meteor has been disguised as the Windows Power Efficiency Diagnostics report tool.2
tool
Meteor S0688
- Type
- malware
- Platform
- Windows
- Created
- 7 March 2022
- Last modified
- 16 April 2025
Meteor is a wiper that was used against Iranian government organizations, including Iranian Railways, the Ministry of Roads, and Urban Development systems, in July 2021. Meteor is likely a newer version of similar wipers called Stardust and Comet that were reportedly used by a group called "Indra" since at least 2019 against private companies in Syria.[1]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference S0688
Meteor can use wmic.exe as part of its effort to delete shadow copies.3
Meteor execution begins from a scheduled task named Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeAll and it creates a separate scheduled task called mstask to run the wiper only once at 23:55:00.4
Meteor can check if a specific process is running, such as Kaspersky's avp.exe.5
Meteor can use PowerShell commands to disable the network adapters on a victim machines.6
Meteor can run set.bat, update.bat, cache.bat, bcd.bat, msrun.bat, and similar scripts.7
Standing S0688
Reach is how much of ATT&CK this tool touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 825 ATT&CK software entries only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
80th percentile · 80% of 825 ATT&CK software entries have this many Enterprise techniques or fewer.
80th percentile · 80% of 825 ATT&CK software entries have this many tactics spanned or fewer.
61% of the population shares a single value across only 22 distinct values, so a percentile here would rank the tie, not the entity.
85% of the population shares a single value across only 8 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
81st percentile · 81% of 825 ATT&CK software entries have this many detection rules per technique or fewer.
Detection coverage S0688
1133 distinct rules cover the 20 techniques recorded for this tool. The 1245 technique-to-rule mappings resolve to 1133 distinct rules, because one rule can cover several techniques. 743 Sigma · 390 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org