Last seven days
- First activity
- Jul 28, 2026
- Last activity
- Jul 28, 2026
- Feed role
- C2
- Host form
- 1 IP / 0 hostnames
GigaWiper is a modular Golang-based Windows malware family that combines backdoor, surveillance, remote administration, and destructive wiper functionality in a single implant.
Profile source: Mallory opens in a new tabGigaWiper
GigaWiper is a modular Golang-based Windows malware family that combines backdoor, surveillance, remote administration, and destructive wiper functionality in a single implant. It was observed in destructive intrusions beginning in October 2025 and is notable for allowing operators to maintain covert control of compromised systems before selectively triggering irreversible sabotage.
The malware has been described as an amalgamation of multiple previously separate malware families. High-confidence reporting links parts of its destructive functionality to Crucio and FlockWiper, with the larger framework embedding a standalone physical-disk wiper alongside additional command-and-control and system-management features. GigaWiper supports roughly 20 operator commands covering remote execution, system profiling, process and service management, registry interaction, screenshot capture, continuous screen recording, file upload, event-log clearing, and hidden VNC-like remote desktop control with keyboard and mouse input.
Its destructive capabilities include raw physical disk wiping, multi-pass wiping of the Windows installation drive, and faux-ransomware-style file encryption that intentionally discards generated encryption material, making recovery by decryption impossible. It can also sabotage system recovery and boot functionality, including actions that leave affected devices unable to start normally. This design gives operators flexibility to shift from espionage and post-compromise control to overt disruption on demand.
GigaWiper establishes persistence on Windows by masquerading as a OneDrive-related component and creating a recurring scheduled task, while also storing execution state in the registry. Its command-and-control architecture is unusual in that it uses RabbitMQ over AMQP for tasking and Redis for status or result handling; reporting also notes use of MinIO tooling for file upload or exfiltration. The malware can modify firewall settings to support its remote-control channel and includes defense-evasion behavior such as clearing Windows event logs.
GigaWiper is assessed to be a post-compromise tool rather than an initial-access payload. Reporting has noted overlap with malware tracked elsewhere as BlueRabbit or BLUERABBIT, and some external reporting associated related activity with Iran-linked targeting of Israeli organizations; however, definitive attribution for GigaWiper itself has not been publicly confirmed. The malware represents an evolution from single-purpose wipers toward a unified intrusion platform that supports reconnaissance, surveillance, remote control, exfiltration, persistence, and destructive operations from one implant.
C2 tracking
Derp observations, rolling seven-day window
Samples
Reported operators
Microsoft has taken apart a destructive Windows backdoor it calls GigaWiper. What stands out is how it is built: not one tool but three older destructive programs bolted into one, offered as commands the operator can choose from.
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.