GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware
ID: cd96bc73-329f-51c1-bc0e-61c789598935
STIX ID: report--cd96bc73-329f-51c1-bc0e-61c789598935
Feed Name: Microsoft Security
Microsoft Threat Intelligence analyzed 'GigaWiper', a modular Golang backdoor observed in October 2025 that consolidates multiple destructive families (physical-disk wipers, a non-recoverable ‘ransomware’ variant, and a FlockWiper-derived multi-pass wiper) into on-demand backdoor commands; it implements RabbitMQ/Redis C2, persistent scheduled tasks, extensive management and espionage capabilities (screenshots, recording, keylogging stubs, VNC-like control), and includes IOCs (SHA-256 hashes, IPs) plus detection and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
