BLUERABBIT Backdoor Targets Windows Systems with Encryption and Wiping Capabilities
ID: 467e28f0-34af-5a5a-a011-933016d5dd20
STIX ID: report--467e28f0-34af-5a5a-a011-933016d5dd20
Feed Name: ThreatCluster
Threat Score
BLUERABBIT is a Golang-based backdoor observed since March 2026 targeting Windows systems—primarily Israeli organizations—capable of data exfiltration, encrypting files with a .candy extension, and performing destructive disk wiping; activity is attributed to Iranian-linked actors, uses remote-access and system-profiling vectors, exfiltrates to attacker-controlled cloud storage, and is currently under investigation, prompting heightened defensive measures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
