Wiping Malware Learns to Spy and Pretend to Extort
The shift is from a single-purpose wiper to a modular implant that can destroy, fake extortion, and watch the victim from the same backdoor. That breaks the usual ransomware assumption that the main problem is file recovery; here the machine can be rendered unrecoverable, and the attacker can still keep live control.
Microsoft says GigaWiper is a Golang backdoor it identified in October 2025 that bundles disk wiping, fake ransomware, system-level sabotage, screenshots, hidden VNC, and other control functions into one platform. The destructive commands borrow from older families including Crucio and FlockWiper, and one mode wipes raw disk content and partition metadata outright.
The forward risk is a reusable destructive toolset, not a one-off wiper. That means compromise can combine permanent data loss with active surveillance on the same host.