SentinelLabs linked the Meteor wiper to the cyberattack that disrupted Iranian rail service on July 9, 2021, and named the wider operation MeteorExpress. Its analysis reconstructed much of how the malware was deployed and damaged systems, but not how attackers first got in. Attribution is also disputed: Check Point Research later assessed that the Iran attacks were linked to Indra, while SentinelLabs said it could not then connect the activity to a known group.
What happened to Iran’s rail system?
On July 9, 2021, Iranian rail service was disrupted in an incident involving destructive malware. SentinelLabs reported that station information boards displayed the message “long delays due to cyber attacks” and directed passengers to “more information: 64411,” a number it identified as the office number of Supreme Leader Ali Khamenei. The display defacement made the disruption visible to travelers, but the available reporting does not establish a reliable total for delayed or canceled trains.
Check Point Research separately reported attacks against Iranian Railways on July 9 and the Ministry of Roads and Urban Development on July 10. It said ministry websites went out of service after the cyber-disruption. Those reports concern related activity on two dates; the railway disruption and the ministry-system incident should not be collapsed into one event.
What do Meteor and MeteorExpress mean?
SentinelLabs uses Meteor for the wiper malware and MeteorExpress for the broader campaign. The campaign name came from artifacts in the malware analysis: its encrypted log behavior included the string “Meteor has started,” which researchers interpreted as the attackers’ internal name for the wiper.
#1 Best Overall
- Experience the joy of building with this Nifeliz articulated steam locomotive model toy. Assemble this model kit following the detailed instructions and immerse yourself in the fascinating world of steam trains.
- Once assembled, this Big Boy locomotive model is a stunning addition to any collection. The ideal size and authentic design make this steam train replica a standout piece, impressing both enthusiasts and casual observers.
- What sets this steam train model apart is its realistic styling with silver electroplated painted parts. Its track can be securely attached to the black base for stability, along with a noticeable display sign on the side.
- From the intricately designed wheels to the highly replicated smokestack and cab, every aspect of this model steam train has been meticulously crafted to ensure an authentic representation of the prototype.
- This Nifeliz steam locomotive building toy comes in an elegant cardboard box, making it a great option for giving as a gift. The considerate packaging adds to the overall enjoyment of building and owning the toy.
Meteor was destructive malware, not ordinary ransomware. SentinelLabs describes it overwriting selected files with zero bytes and deleting them; the reporting does not describe a ransom demand as the purpose of the malware.
How did the attack chain work?
SentinelLabs reconstructed a deployment chain from an incomplete set of recovered samples. The report describes attackers using Group Policy to distribute a CAB file, with batch scripts coordinating components extracted from RAR archives. One script checked target hostnames; other stages prepared systems, affected boot configuration, and launched the wiper.
Rank #2
- 【Scale Model Vehicle】It is inspired by the evolution of road vehicles back to the 19 century.Characteristic vehicles of the era are replicated into the mini scale models with detailed structures.
- 【No Glue Needed】Unique Mechanical 3D Puzzle,laser-cut ply wood,no tonxic,environmental friendly,smooth wooden board.All pieces are pre-cut,no glue needed.The interlocking mechanisms are pretty ingenious.
- 【Detailed English Instruction】Making this mechanical model toy requires not only attentiveness but also patience.Feel the pride of assembling this entire IQ toy set-up with your very own hands.
- 【Creative Gift】What a fascinating thing to see the mechanical miracle coming to life by your own hands.Best Holiday gift for your boyfriend,girlfriend,husband,wife who is model builder or puzzle lover.It looks so cool and creates a decent challenge for an adult.
- 【Perfect Decoration】The 3D wooden puzzle has decorative designs that look captivating in the finished product.It is a challenge for both eyes and hands,and also a perfect display for stylish collections!
The wiper used an encrypted configuration to specify file paths and patterns to target. After overwriting and deleting matched files, it attempted to remove volume shadow copies. SentinelLabs also described measures intended to make recovery or administration harder, including removing a machine from its domain and changing local user passwords. This reconstruction explains malware deployment and behavior inside the environment; it does not establish how the attackers initially accessed the network.
Other components and recovery effects
SentinelLabs identified mssetup.exe as a screen locker, a component with a distinct role from the file-wiping malware. Another executable, nti.exe, was reported by Padvish as an MBR corruptor. SentinelLabs could not recover that binary and therefore could not independently verify its behavior; its exact destructive effect should be treated as unconfirmed by that analysis.
Rank #3
- Detailed driver's cab
- Movable Wheels
- 87 parts, skill level 3
- Decals for 2 Union Pacific versions
- Illustrated assembly instructions
MITRE ATT&CK catalogs Meteor as Windows malware under software ID S0688. Its entry includes data destruction, local account access removal, PowerShell, and Windows command-shell behaviors. The record, last modified April 16, 2025, is a reference for observed malware behaviors—not evidence identifying the people or group behind an operation. See MITRE ATT&CK’s Meteor entry.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Who was behind the attack?
Public attribution remains an assessment, not a confirmed claim of responsibility. SentinelLabs’ original report said the researchers could not connect the operation to a previously identified group and warned against treating attribution as settled. Its author, Juan Andrés Guerrero-Saade, wrote: “At this time, any form of attribution is pure speculation and threatens to oversimplify a raging conflict between multiple countries with vested interests, means, and motive.” The statement appeared in his SentinelLabs report, which was updated June 18, 2025.
Rank #4
- 【1:18 Scale Train Model Vehicle】This is designed as a 1:18 Scale Model Vehicle for you to play with, You can pose, with 1:18 dolls, to create an imaginary scene of your mind.
- 【Self Assemble 3D Wooden Puzzle】This is a DIY kit that requires your hands-on work to complete. This mechanical wooden puzzle toy uses precision laser cutting of high-quality plywood, which is safe and convenient.
- 【Detailed Instructions and No Glue Needed】You can follow our Detailed Instructions to assemble it step by step, no glue needed, Just need patience, after 2-4 hours, you will get an unique car model.
- 【Gifts and Desk Decor】This is an good gift choice for any occasion. At Christmas, new year, birthday, Valentine's day as a gift to adults, boyfriend, son, father, ect. In addition, it can be used as a family decoration, in the study, on the desk.
- 【Matters Needing Attention】Be careful to connect the parts in a complete and solid way to ensure that it runs well. Don't put it in a wet place. If you find product problems,we will help you to solve problems. Thank you.
Check Point Research later assessed that Indra was responsible for the Iran attacks, comparing them with operations against private companies in Syria during 2019–2020. Its reasoning included similarities in tools and tactics, target relationships, and signs of prior knowledge of victim networks. Check Point said Indra did not publicly claim the Iran attacks, unlike earlier operations. This is Check Point’s attribution assessment; it is not a public admission or a universally established conclusion.
The analyses emphasize different evidence. SentinelLabs focused on reconstructing the campaign from recovered files and components; Check Point compared the Iran activity with earlier operations. Neither account turns the public evidence into a definitive, publicly acknowledged attribution.
Recommended Free Tools
Quick Recap
Best Value
- 🚂 Classic Design – This Steam Train model brings designed charm to life with intricate detailing. With 405 wooden pieces, it conveyed the spirit of vintage steam train, making it a captivating display piece for any space.
- 🛠️ Hands-On Craft – Assemble this model step-by-step, enhancing patience and fine motor skills. Designed for adults, it’s a challenging and rewarding DIY project that delivers a sense of achievement.
- 🎁 Gift of Creativity – This train puzzle makes an excellent gift for birthdays, holidays, or special occasions. Its unique theme and artistic design appeal to hobbyists, collectors, and train enthusiasts.
- 🌍 Premium Quality – Made from eco-friendly, smooth, and durable wood, each piece connects seamlessly for an enjoyable building experience. It’s crafted to ensure long-lasting display value.
- 📐 STEM Learning – With STEM-inspired design, this 3D puzzle improves problem-solving, spatial reasoning, and creativity, making it both an educational and enjoyable craft. It's a perfect activity for family bonding or solo exploration.
What remains unknown?
- Initial access: The entry route into the affected environment has not been established. FortiGuard Labs said it could not confirm whether vulnerabilities were exploited because details of the intrusion were unavailable. A Group Policy deployment chain describes activity after access, not the initial entry.
- The unrecovered executable: SentinelLabs could not obtain
nti.exe, so its reported MBR-corruption behavior was not independently verified by that team. - Definitive attribution: Check Point’s Indra assessment is based on similarities to earlier activity, while SentinelLabs’ report cautions that attribution is speculative. The public record cited here does not establish a claim of responsibility for the Iran attacks.
Sources and further reading
- SentinelLABS: “MeteorExpress | Mysterious Wiper Paralyzes Iranian Trains with Epic Troll” (original 2021 report; updated June 18, 2025).
- Check Point Research: “Indra — Hackers Behind Recent Attacks on Iran” (2021).
- FortiGuard Labs: “Attack on the Iranian Train System by Meteor Wiper” (July 30, 2021).
- SecurityWeek: “Researchers Link Mysterious ‘MeteorExpress’ Wiper to Iranian Train Cyberattack” (July 29, 2021).
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

