logo

GigaWiper Merges Three Malware Families Into One Destructive Backdoor

ID: 019e8fae-190a-5a1b-a764-186ece2dd095

STIX ID: report--019e8fae-190a-5a1b-a764-186ece2dd095

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-07-10

Date Updated: 2026-07-19

Author: Pierluigi Paganini

...
...

Microsoft researchers discovered GigaWiper, a modular Go backdoor that consolidates three malware families into a single implant combining espionage, remote control (VNC-like access, screenshots, system/process/registry management), and multiple destructive wiping commands (raw disk overwrite, boot/kernel deletion causing unbootable systems, fake irreversible file encryption, multi-pass Windows drive wiping). The backdoor persists as a scheduled task, communicates via RabbitMQ (commands) and Redis (results) with observed C2 IP 185.182.193.21, and reuses code from Crucio and FlockWiper; Microsoft recommends tamper protection, EDR block mode, cloud protection, and blocking known C2 indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.