GigaWiper is a modular Golang-based Windows backdoor that combines espionage-oriented remote administration with multiple destructive payloads in a single implant. It was first observed in destructive intrusions in October 2025 and is designed for post-compromise use, allowing operators to maintain access, conduct surveillance and system management, exfiltrate files, and then trigger irreversible sabotage on demand.
The malware supports persistence by masquerading as a OneDrive-related component and creating a recurring scheduled task. Its command-and-control architecture uses RabbitMQ for tasking and Redis for status and output handling, and observed functionality also includes file upload to remote storage. GigaWiper exposes a broad command set for PowerShell execution, system reconnaissance, antivirus discovery, process and service management, registry modification, screenshot capture, continuous screen recording, event log clearing, and hidden VNC-like remote desktop control with keyboard and mouse input. It also modifies firewall settings to enable remote-access functionality.
GigaWiper is notable for consolidating functionality from at least three previously separate malware families into one operator-selectable framework. Microsoft linked one destructive module to Crucio-derived code that performs fake-ransomware-style encryption using randomly generated keys that are intentionally not retained, rendering affected files unrecoverable and indicating destructive rather than extortion intent. Another destructive component is a Go reimplementation of FlockWiper-style multi-pass wiping logic. Additional destructive routines include raw physical-disk wiping, partition metadata destruction, Windows-drive overwriting, boot-disruption and recovery disabling, and forced system restart or crash behavior intended to leave systems unusable.
This design reflects an evolution from single-purpose wipers toward unified intrusion platforms that support prolonged covert access before switching to destructive action. Public reporting has noted overlap with malware also tracked as BlueRabbit or BLUERABBIT, and some reporting has discussed possible Iran-linked associations, but no definitive public attribution has been confirmed. GigaWiper should be treated as both a backdoor and a destructive malware platform capable of surveillance, remote control, file theft, defense evasion, and irreversible system damage across compromised Windows environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Microsoft has taken apart a destructive Windows backdoor it calls GigaWiper. What stands out is how it is built: not one tool but three older destructive programs bolted into one, offered as commands the operator can choose from.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
Once installed, the malware establishes persistence by creating a scheduled task disguised as “OneDrive Update”. The task is executed when the system starts and subsequently runs once every minute.
Once installed, the malware establishes persistence by creating a scheduled task disguised as “OneDrive Update”. The task is executed when the system starts and subsequently runs once every minute.
The malware establishes persistence by creating a scheduled task named OneDrive Update, while maintaining execution state through the registry key HKCU\SOFTWARE\OneDrive\Environment.
Once installed, the malware establishes persistence by creating a scheduled task disguised as “OneDrive Update”. The task is executed when the system starts and subsequently runs once every minute.
It disguises persistence as a OneDrive updater task... Because these names mimic Microsoft software, the activity blends into normal system noise.
The backdoor supports 20 numbered commands. These cover screenshots, screen recording, process control, log wiping, and system profiling.
These commands allow its operators to execute PowerShell instructions, collect information about the computer and installed antivirus solutions and manage running processes and Windows services.
“GigaWiper” receives commands from its operators through RabbitMQ servers and transmits the results of executed operations via Redis infrastructure.
the malware generates random AES encryption keys and initialization vectors that are intentionally discarded after encryption. Unlike conventional ransomware operations, no mechanism exists for recovering encrypted files because the encryption material is never retained.
a destructive command that derives from Crucio ransomware and encrypts files with randomly generated keys that are never saved, making decryption impossible
allowing cyber threat actors to conduct both quiet espionage activity and destructive wiping operations... ultimately trigger one of multiple destructive commands on demand
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A destructive Windows malware with remote-access capabilities. It establishes persistence via a scheduled task disguised as “OneDrive Update,” receives commands through RabbitMQ and returns results via Redis. It can wipe partition information, overwrite physical drives, erase the Windows system drive, encrypt files with a “.candy” extension using unrecoverable random keys, execute PowerShell, gather host and antivirus information, manage processes and services, modify the registry, capture screenshots, record monitor activity, clear event logs, upload files, and provide VNC-like remote control.
A modular Golang malware platform and backdoor that supports persistence, reconnaissance, surveillance, remote administration, and destructive actions including physical disk wiping, irreversible file encryption, and secure multi-pass data destruction.
A destructive Windows backdoor written in Golang that bundles multiple malware capabilities into one implant, including disk wiping, fake ransomware-style file destruction, remote control, screenshots, screen recording, process control, log wiping, and system profiling. It is deployed post-compromise and can communicate through RabbitMQ, Redis, and MinIO.
Модульный Windows-бэкдор на Go с деструктивными и шпионскими функциями. Может закрепляться в системе под видом OneDrive, выполнять удаленные команды, делать скриншоты, записывать экран, открывать скрытую VNC-сессию, запускать PowerShell, собирать системную информацию, управлять процессами/службами, редактировать реестр, очищать журналы событий, эксфильтровать файлы и уничтожать данные несколькими способами, включая вайпинг диска и псевдошифрование без возможности восстановления.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.