Malware · 63 days ago
The shift is from a single-purpose wiper to a modular implant that can destroy, fake extortion, and watch the victim from the same backdoor. That breaks the usual ransomware assumption that the main problem is file recovery; here the machine can be rendered unrecoverable, and the attacker can still keep live control.
Microsoft says GigaWiper is a Golang backdoor it identified in October 2025 that bundles disk wiping, fake ransomware, system-level sabotage, screenshots, hidden VNC, and other control functions into one platform. The destructive commands borrow from older families including Crucio and FlockWiper, and one mode wipes raw disk content and partition metadata outright.
The forward risk is a reusable destructive toolset, not a one-off wiper. That means compromise can combine permanent data loss with active surveillance on the same host.
5 sources covering this story
GigaWiper Lets Threat Actors Choose Their Own Destructive Attack
A modular implant borrows from various malware families to combine both backdoor and wiper activities to maximize impact and minimize operational output.
New ‘GigaWiper’ Malware Combines Espionage & Destructive Capabilities
A new multi-purpose backdoor allows cyber threat actors to conduct both quiet espionage activity and destructive wiping operations
GigaWiper Combines Multiple Malware for System-Level Sabotage
The backdoor’s destructive capabilities include a standalone wiper, ransomware encryption, and a multi-pass wiping command.
New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware
Microsoft details GigaWiper, a Windows backdoor that bundles disk wiping, fake ransomware, and remote control into one destructive tool.
GigaWiper, also tracked as BLUERABBIT, is a destructive backdoor that combines multiple wiping and ransomware-like capabilities into a single operational platform.
Part of the PlainSec briefing for 2026-07-14