logo

BLUERABBIT Backdoor Targets Windows Systems with Encryption and Wiping Capabilities

ID: 467e28f0-34af-5a5a-a011-933016d5dd20

STIX ID: report--467e28f0-34af-5a5a-a011-933016d5dd20

Feed Name: ThreatCluster

Threat Score
87/100

Date Published: 2026-06-11

Date Updated: 2026-06-12

...
...

BLUERABBIT is a Golang-based backdoor observed since March 2026 targeting Windows systems—primarily Israeli organizations—capable of data exfiltration, encrypting files with a .candy extension, and performing destructive disk wiping; activity is attributed to Iranian-linked actors, uses remote-access and system-profiling vectors, exfiltrates to attacker-controlled cloud storage, and is currently under investigation, prompting heightened defensive measures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.