FlockWiper is a destructive Windows wiper written in C that emerged in 2025 and is associated with later destructive tooling through code reuse and reimplementation. Its core function is to overwrite the Windows installation drive repeatedly using multiple data patterns in order to destroy data and hinder forensic recovery. The malware is notable for secure multi-pass wiping logic that was later ported to Go and incorporated into the modular GigaWiper framework as one of its destructive commands.
FlockWiper is linked by code lineage to a broader cluster of destructive malware components that also includes Crucio-derived functionality, and shared developer artifacts suggest common development relationships among these tools. In later operations, FlockWiper-style wiping logic was embedded into a post-compromise backdoor platform that combined espionage, remote administration, and on-demand sabotage, indicating that FlockWiper served as a reusable destructive component rather than only a standalone payload.
High-confidence reporting supports FlockWiper as a dedicated wiper targeting Windows systems. Its primary purpose is irreversible data destruction through repeated overwriting of disk contents, making recovery difficult and reducing the likelihood of successful forensic restoration.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
"These included a raw disk wiper that overwrites physical disks and destroys partition information... and a multipass secure wiper ... that repeatedly overwrites files to hinder forensic recovery."
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A previously separate malware family whose secure multi-pass wiping functionality was integrated into GigaWiper.
A wiper malware family whose multi-pass disk wiping logic appears to have been incorporated into GigaWiper.
Вайпер, переписанный на Go и встроенный как компонент GigaWiper; предназначен для многократной перезаписи системного диска разными шаблонами с целью необратимого уничтожения данных.
A wiper whose file-overwrite approach is reused by a GigaWiper destructive module to repeatedly overwrite files and impede forensic recovery.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.