A Novel Malware Allows Attackers to Choose Their Own Destructive Path
Cybersecurity researchers have discovered a sophisticated malware that lets attackers choose how they want to destroy a targeted system. Dubbed GigaWiper, this modular implant combines elements from various malware families to provide both backdoor and wiper capabilities. The implications are significant, as GigaWiper’s flexibility gives threat actors the ability to maximize their impact while minimizing their operational footprint.
Initially thought to be a simple backdoor, GigaWiper was first spotted during “destructive wiper activity” in October 2025. However, upon closer inspection, researchers realized that this malware is more complex than initially assumed. It combines multiple malware families and gives attackers the flexibility to choose how they want to destroy a system via on-demand backdoor commands once they’ve established control of the victim network.
The versatility of GigaWiper is its most striking feature. It can deploy various destructive payloads, including disk wiping, fake ransomware, and system-level sabotage. According to Microsoft’s Threat Intelligence blog, which first identified the malware, “GigaWiper [is] a versatile implant that combines robust command-and-control (C2) capabilities with multiple destructive payloads.” This flexibility is a significant departure from traditional wipers, which are typically designed for destructive attacks with no option for recovery.
The modular nature of GigaWiper also allows attackers to choose the most damaging action at the optimal moment. Unlike traditional wipers, which are often “fire-and-forget,” GigaWiper provides persistent access, remote control, reconnaissance, and command execution capabilities long before a destructive payload is triggered. This shift in behavior requires security teams to adjust their focus from detecting the wiping event itself to identifying earlier signs of compromise in the system.
The backdoor component of GigaWiper supports around 20 commands that allow attackers to execute various actions, including remote shell execution, file management, and process control. This extensive operational capability enables threat actors to control infected systems and deploy additional tooling before launching any disruptive actions.
Microsoft identified three distinct destructive modules within GigaWiper: a raw disk wiper that overwrites physical disks; fake ransomware derived from the Crucio family that encrypts files using random keys discarded after encryption; and a multipass secure wiper based on FlockWiper. These modules are designed to give organizations little chance of recovering destroyed data and assets.
The implications of GigaWiper’s modularity extend beyond its ability to destroy systems. The back-end C2 infrastructure also demonstrates flexibility, using RabbitMQ and Redis instead of traditional HTTP or DNS communications. This modular design makes it more challenging for security teams to detect and respond to the malware.
In light of these findings, organizations must adjust their security posture to address this new threat. This means shifting focus from detecting wiping events to identifying earlier signs of compromise in the system. By being aware of GigaWiper’s capabilities and adapting their defenses accordingly, organizations can better protect themselves against this sophisticated malware.
Source: Dark Reading — 2026-07-13