All incidents

GigaWiper malware blends espionage backdoor with destructive wiper

malwareclosedJul 9, 2026 — Jul 13, 2026
GigaWiper malware blends espionage backdoor with destructive wiper

MICROSOFT has disclosed a new modular malware dubbed GigaWiper that merges espionage backdoor functions with destructive wiping capabilities, signalling a shift in how attackers combine surveillance and sabotage. The discovery was detailed in a company blog post Microsoft Security Blog.

GigaWiper is written in the Go programming language and presents operators with roughly twenty distinct commands that cover reconnaissance, persistence and destruction. It achieves persistence through a Windows scheduled task that launches the implant at startup and maintains contact with its controllers via RabbitMQ queues and Redis storage. Among its destructive options are low‑level disk wiping, partition table corruption and file‑encrypting ransomware that leaves no viable decryption key.

Analysts first observed the malware in the wild during a series of wiper incidents in October 2025, noting that its modular design lets an attacker choose a specific effect on the fly without deploying a new implant. The same binary can switch from silent screen capture and file exfiltration to a full drive wipe based on the command received. Communication with the command‑and‑control infrastructure relies on standard messaging protocols, which helps the traffic blend with legitimate enterprise services.

Although no specific threat actor has been publicly linked to GigaWiper, its appearance coincides with a rise in attacks that seek to gather intelligence before rendering a target system inoperable. This approach increases the potential damage because adversaries can harvest credentials, configuration data or intellectual property before pulling the destructive trigger. Security researchers note that the blurring of espionage and wiper functions reflects a broader trend toward multi‑purpose malware.

The consolidation of several malware families into a single backdoor reduces the logistical burden for attackers and complicates defence because traditional indicators of compromise may only appear after a destructive command has been issued. By combining spying and wiping, GigaWiper can remain undetected longer, gathering valuable data while appearing benign. This flexibility means that network defenders must watch for subtle anomalies rather than obvious ransomware notes or known wiper signatures.

Defenders should ensure that tamper protection is enabled on all Windows endpoints to block unauthorised changes to scheduled tasks or service configurations. Monitoring for outbound connections to atypical RabbitMQ or Redis ports, as well as unexpected launches of screen capture utilities, can raise early alerts. Behaviour‑based endpoint detection and response tools are effective at flagging raw disk access attempts or the execution of unfamiliar binaries that masquerade as legitimate processes.

Organisations are also advised to review proxy and firewall logs for connections to domains or IP addresses associated with GigaWiper’s command‑and‑control infrastructure, share any indicators of compromise with trusted information sharing groups, and consider disabling unused remote administration services that could be abused for initial infection. Keeping anti‑malware signatures and system patches up to date remains a basic but essential layer of defence.

Intelligence briefing updated Jul 13, 2026

Root sourcewww.microsoft.com
Timeline Coverage

Swipe to explore timeline