logo

New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware

ID: 7b76bbfb-1f46-5a82-863d-c607544dcee8

STIX ID: report--7b76bbfb-1f46-5a82-863d-c607544dcee8

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-07-09

Date Updated: 2026-07-18

Author: [email protected] (The Hacker News)

...
...

**Executive summary:** Microsoft and Binary Defense analysed a destructive Windows backdoor tracked as GigaWiper (also reported as BLUERABBIT) that bundles three destructive modules (raw disk wiper, Windows-drive multi-pass wiper, and fake ransomware based on Crucio) alongside remote-control/espionage features; Microsoft links code to FlockWiper/Crucio and notes likely Iran-nexus activity targeting Israeli organizations, provides IoCs (hashes, command servers) and detection/mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.