Microsoft Uncovers GigaWiper, a Backdoor Designed for Destruction on Demand
Microsoft says the malware can stay hidden for surveillance before operators trigger partition removal, multi-pass drive overwrites or file encryption with no recovery option.
- Microsoft Threat Intelligence described GigaWiper in a Thursday blog, a modular backdoor granting operators remote control over Windows systems before triggering permanent destruction.
- GigaWiper combines code from Crucio ransomware and FlockWiper, functioning as a "Swiss Army" knife for attackers seeking both surveillance and destructive capabilities.
- The malware supports 20 command codes for tasks like screen recording and system management; encryption uses AES-256 without saving keys, preventing any file recovery.
- Once installed, GigaWiper maintains persistence through a scheduled task disguised as OneDrive Update, receiving commands via RabbitMQ while returning results through Redis.
- Microsoft recommends enabling tamper protection and monitoring suspicious scheduled tasks, as the backdoor allows operators to clear Windows event logs and modify Windows Firewall rules.
11 Articles
11 Articles
Destructive Windows backdoor stuffs multiple wipers and ransomware code into a single package
A newly identified destructive Windows backdoor combines ransomware-like encryption with multiple data-wiping features, according to Microsoft. Last October, the Redmond threat-hunting team first spotted attacks using the Golang-based implant they've named GigaWiper. Its developers stuffed multiple malware families into the software as on-demand commands, giving criminals a Swiss Army knife of command-and-control (C2) and destructive capabilitie…
Microsoft discovers new multi-malware package 'GigaWiper' capable of deploying wipers and ransomware
Microsoft warns of “GigaWiper,” a destructive malware attributed to Iranian group CyberAv3ngers that combines multiple variants into oneIt can wipe drives, encrypt files with a fake ransomware extension, or overwrite Windows partitions, while also spying via screenshots, VNC sessions, and system data theftThe malware hides under fake OneDrive tasks and registry keys, showing both espionage and sabotage capabilities with no recovery path for vict…
Microsoft uncovers GigaWiper, a backdoor designed for destruction on demand
The modular Golang backdoor combines remote administration, multiple disk-wiping logics, and a Crucio-derived ransomware module that deliberately discards encryption keys, making recovery impossible.
Destructive Windows backdoor stuffs multiple wipers and ransomware code into a single package | #ransomware | #cybercrime - National Cyber Security Consulting
security Microsoft says GigaWiper combines at least 3 malware families into one modular tool A newly identified destructive Windows backdoor combines ransomware-like encryption with multiple data-wiping features, according to Microsoft. Last October, the Redmond threat-hunting team first spotted attacks using the Golang-based implant they've named GigaWiper. Its developers stuffed multiple malware families into the software […] Thank you for su…
GigaWiper Combines Multiple Malware for System-Level Sabotage
The backdoor’s destructive capabilities include a standalone wiper, ransomware encryption, and a multi-pass wiping command. The post GigaWiper Combines Multiple Malware for System-Level Sabotage appeared first on SecurityWeek.
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium




