Skip to content

GigaWiper

GigaWiper is a modular Golang-based Windows backdoor that combines espionage-oriented remote administration with multiple destructive payloads in a single implant.

Profile source: Mallory opens in a new tab

GigaWiper

Family profile

GigaWiper is a modular Golang-based Windows backdoor that combines espionage-oriented remote administration with multiple destructive payloads in a single implant. It was first observed in destructive intrusions in October 2025 and is designed for post-compromise use, allowing operators to maintain access, conduct surveillance and system management, exfiltrate files, and then trigger irreversible sabotage on demand.

The malware supports persistence by masquerading as a OneDrive-related component and creating a recurring scheduled task. Its command-and-control architecture uses RabbitMQ for tasking and Redis for status and output handling, and observed functionality also includes file upload to remote storage. GigaWiper exposes a broad command set for PowerShell execution, system reconnaissance, antivirus discovery, process and service management, registry modification, screenshot capture, continuous screen recording, event log clearing, and hidden VNC-like remote desktop control with keyboard and mouse input. It also modifies firewall settings to enable remote-access functionality.

GigaWiper is notable for consolidating functionality from at least three previously separate malware families into one operator-selectable framework. Microsoft linked one destructive module to Crucio-derived code that performs fake-ransomware-style encryption using randomly generated keys that are intentionally not retained, rendering affected files unrecoverable and indicating destructive rather than extortion intent. Another destructive component is a Go reimplementation of FlockWiper-style multi-pass wiping logic. Additional destructive routines include raw physical-disk wiping, partition metadata destruction, Windows-drive overwriting, boot-disruption and recovery disabling, and forced system restart or crash behavior intended to leave systems unusable.

This design reflects an evolution from single-purpose wipers toward unified intrusion platforms that support prolonged covert access before switching to destructive action. Public reporting has noted overlap with malware also tracked as BlueRabbit or BLUERABBIT, and some reporting has discussed possible Iran-linked associations, but no definitive public attribution has been confirmed. GigaWiper should be treated as both a backdoor and a destructive malware platform capable of surveillance, remote control, file theft, defense evasion, and irreversible system damage across compromised Windows environments.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Persistence
  • Post Exploitation
  • Process Injection
  • Reconnaissance

Reported operators

Threat actors

1 named in public reporting
CyberAv3ngers

Microsoft has taken apart a destructive Windows backdoor it calls GigaWiper. What stands out is how it is built: not one tool but three older destructive programs bolted into one, offered as commands the operator can choose from.

MITRE ATT&CK

GigaWiper in ATT&CK

37 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.