logo

GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware

ID: cd96bc73-329f-51c1-bc0e-61c789598935

STIX ID: report--cd96bc73-329f-51c1-bc0e-61c789598935

Feed Name: Microsoft Security

Threat Score
85/100

Date Published: 2026-07-09

Date Updated: 2026-07-17

Author: Microsoft Threat Intelligence

...
...

Microsoft Threat Intelligence analyzed 'GigaWiper', a modular Golang backdoor observed in October 2025 that consolidates multiple destructive families (physical-disk wipers, a non-recoverable ‘ransomware’ variant, and a FlockWiper-derived multi-pass wiper) into on-demand backdoor commands; it implements RabbitMQ/Redis C2, persistent scheduled tasks, extensive management and espionage capabilities (screenshots, recording, keylogging stubs, VNC-like control), and includes IOCs (SHA-256 hashes, IPs) plus detection and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.