GigaWiper Lets Threat Actors Choose Their Own Destructive Attack
ID: 9df0adcb-0e67-5d05-9e6a-c4588e9e28ca
STIX ID: report--9df0adcb-0e67-5d05-9e6a-c4588e9e28ca
Feed Name: Dark Reading
GigaWiper (also tracked as BlueRabbit) is a modular Golang-based backdoor observed performing destructive wiper activity; it combines persistent C2 (using RabbitMQ/AMQP and Redis) with on-demand destructive modules — raw disk overwriter, fake (irrecoverable) Crucio-derived ransomware, and a multipass FlockWiper-based overwriter — enabling attackers to maintain access, perform reconnaissance, and time destruction for maximum impact. Microsoft and other telemetry observed active destructive behavior and published detection and mitigation guidance, while attribution remains unconfirmed though prior reporting linked similar activity to an Iran-aligned actor.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
