Microsoft says a threat actor has used a destructive Windows backdoor called GigaWiper for more than eight months to maintain access and sabotage infected systems. First seen in October 2025, the Go-based malware combines older wiping components with backdoor functions, supports command-and-control through RabbitMQ and Redis, and can run PowerShell, upload files, take screenshots, record screens, trigger a Blue Screen of Death, encrypt files in both reversible and destructive modes, and wipe disks at the physical-drive level.
Why it matters: This is not just another infostealer or ransomware sample: it gives attackers a single tool for stealthy access and for crippling machines on demand. Defenders should hunt for the malware’s persistence and command-and-control activity, especially RabbitMQ, Redis, MinIO Client, and destructive commands, because the impact can range from spying to irreversible data loss.
2026.07.10
99% relevant
This article is a report on the same Microsoft disclosure, adding plain-language details on GigaWiper’s modular design, its use of RabbitMQ and Redis for command-and-control, its disk-wiping and no-recovery encryption functions, and Microsoft’s statement that the tool combines components from Crucio ransomware, a Go version of FlockWiper, and a standalone disk wiper.
Ionut Arghire
2026.07.10
100% relevant
This article establishes a distinct malware-tracking story centered on Microsoft's disclosure of GigaWiper as a named destructive backdoor with combined espionage, encryption, and wiping capabilities.
← Back to all stories