← All stories
● Covered by 2 sources · 2 reportsMedium impact

GigaWiper: New Sophisticated Windows Backdoor with Destructive Capabilities

🔄 Updated 84d ago — new reporting from SecurityWeek
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • GigaWiper targets Windows systems with multiple destructive capabilities.
  • It combines disk wiping, fake ransomware, and spyware functions.
  • Developed in Go and includes robust command-and-control capabilities.
  • Likely used by threat actors linked to attacks on Israeli targets.
  • Detected by both Microsoft and Binary Defense with matching characteristics.

Introduction to GigaWiper

Microsoft has analyzed a newly identified backdoor for Windows systems known as GigaWiper. This malware is noted for its sophisticated structure and multiple destructive capabilities, marking a significant shift in the functionalities of typical wiper malware.

Technical Specifications and Capabilities

GigaWiper is a backdoor that runs on Windows and is written in Go. It comprises a series of older destructive programs that an operator can execute individually via numbered commands. These capabilities include wiping the entire disk, deploying fake ransomware, and executing spyware functions.

The malware's wiping function operates at the disk level and involves thorough erasure processes that could disrupt system operations. Additionally, the fake ransomware encrypts files without saving the decryption key, simulating a ransomware attack without the possibility of data recovery.

Potential Threat Connections

GigaWiper has surfaced in reports from Binary Defense as BLUERABBIT, with both companies listing identical file hashes and command server details. There are indications, as noted by the Google Threat Intelligence Group, suggesting the malware’s use by a group with potential connections to Iran, targeting Israeli organizations.

Implications and Defensive Measures

The evolution of malware like GigaWiper highlights the need for early detection and secure offline backups to mitigate risk. As the malware does not rely on a single exploit or vulnerability, traditional patching is ineffective, emphasizing proactive cyber defense strategies.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Microsoft has uncovered GigaWiper, a sophisticated malware combining a backdoor and wiper with multiple destructive capabilities. Its modular design marks a shift in wiper malware, enabling not just destruction but also potential data extortion.

Microsoft has dissected the GigaWiper backdoor, highlighting its capabilities which include disk wiping, fake ransomware, and spyware functions. This sophisticated malware targets Windows machines and potentially connects to cyber threats aimed at Israeli organizations, emphasizing the need for robust detection and backup measures.