Microsoft has taken apart a destructive Windows backdoor it calls GigaWiper. What stands out is how it is built: not one tool but three older destructive programs bolted into one, offered as commands the operator can choose from.
GigaWiper
GigaWiper is a modular Golang malware family for Windows that combines backdoor, surveillance, remote-administration, exfiltration, and destructive capabilities in a single implant.
Profile source: Mallory opens in a new tabGigaWiper
Family profile
GigaWiper is a modular Golang malware family for Windows that combines backdoor, surveillance, remote-administration, exfiltration, and destructive capabilities in a single implant. It has been described as a post-compromise intrusion platform that allows operators to maintain access, conduct reconnaissance and monitoring, and then trigger irreversible system destruction on demand.
Observed functionality includes persistence via a scheduled task masquerading as a legitimate OneDrive updater, command-and-control using RabbitMQ for tasking and Redis for status and output, PowerShell execution, process and service management, registry modification, system profiling, screenshot capture, continuous screen recording, event-log clearing, file upload, and a VNC-like hidden remote-control capability with keyboard and mouse interaction. The malware also modifies Windows Firewall rules to support its remote-access channel.
GigaWiper incorporates multiple destructive modules. These include a raw physical-disk wiper that overwrites disk content and damages partition information, a Windows-drive secure wiper that performs multi-pass overwrites, and a faux-ransomware routine derived from Crucio that encrypts files with randomly generated keys that are intentionally not retained, making recovery impossible and indicating destructive rather than extortion intent. Microsoft also linked another destructive component to FlockWiper, assessing that GigaWiper consolidates functionality from at least three previously separate malware families into one framework.
The malware was first observed in destructive activity in October 2025. Reporting consistently characterizes it as a Windows-focused implant used after initial access has already been obtained. Some external reporting has associated overlapping tooling tracked as BlueRabbit or BLUERABBIT with Iran-linked activity targeting Israeli organizations, but definitive attribution for GigaWiper itself has not been publicly confirmed. Technical overlap with Zebrocy has also been noted in some samples, but available information is insufficient to support firm attribution on that basis.
Capabilities
- Defense Evasion
- Exfiltration
- Persistence
- Post Exploitation
- Process Injection
- Reconnaissance
Reported operators
Threat actors
1 named in public reportingMITRE ATT&CK