Microsoft details GigaWiper backdoor that can spy on systems, encrypt files, and wipe Windows disks

Microsoft says a threat actor has used a destructive Windows backdoor called GigaWiper for more than eight months to maintain access and sabotage infected systems. First seen in October 2025, the Go-based malware combines older wiping components with backdoor functions, supports command-and-control through RabbitMQ and Redis, and can run PowerShell, upload files, take screenshots, record screens, trigger a Blue Screen of Death, encrypt files in both reversible and destructive modes, and wipe disks at the physical-drive level.
Why it matters: This is not just another infostealer or ransomware sample: it gives attackers a single tool for stealthy access and for crippling machines on demand. Defenders should hunt for the malware’s persistence and command-and-control activity, especially RabbitMQ, Redis, MinIO Client, and destructive commands, because the impact can range from spying to irreversible data loss.

Sources

Destructive Windows backdoor stuffs multiple wipers and ransomware code into a single package
2026.07.10 99% relevant
This article is a report on the same Microsoft disclosure, adding plain-language details on GigaWiper’s modular design, its use of RabbitMQ and Redis for command-and-control, its disk-wiping and no-recovery encryption functions, and Microsoft’s statement that the tool combines components from Crucio ransomware, a Go version of FlockWiper, and a standalone disk wiper.
GigaWiper Combines Multiple Malware for System-Level Sabotage
Ionut Arghire 2026.07.10 100% relevant
This article establishes a distinct malware-tracking story centered on Microsoft's disclosure of GigaWiper as a named destructive backdoor with combined espionage, encryption, and wiping capabilities.
← Back to all stories