GigaWiper Merges Three Malware Families Into One Destructive Backdoor
ID: 019e8fae-190a-5a1b-a764-186ece2dd095
STIX ID: report--019e8fae-190a-5a1b-a764-186ece2dd095
Feed Name: Security Affairs
Microsoft researchers discovered GigaWiper, a modular Go backdoor that consolidates three malware families into a single implant combining espionage, remote control (VNC-like access, screenshots, system/process/registry management), and multiple destructive wiping commands (raw disk overwrite, boot/kernel deletion causing unbootable systems, fake irreversible file encryption, multi-pass Windows drive wiping). The backdoor persists as a scheduled task, communicates via RabbitMQ (commands) and Redis (results) with observed C2 IP 185.182.193.21, and reuses code from Crucio and FlockWiper; Microsoft recommends tamper protection, EDR block mode, cloud protection, and blocking known C2 indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
