A Sophisticated Wiper Malware, GigaWiper, Allows Threat Actors to Combine Destructive Capabilities with Espionage-Grade Backdoor
A highly advanced malware, dubbed GigaWiper, has been used by a threat actor for over eight months to devastating effect. According to Microsoft, the malware combines multiple system-level sabotage capabilities with robust command-and-control (C&C) features, making it a formidable tool in the hands of its operators.
GigaWiper is a Go-based backdoor that incorporates elements from various malware families, including ransomware and wipers. This modular design allows the attacker to execute different commands on demand, such as wiping entire drives, encrypting files, or uploading sensitive data to remote servers. The malware’s capabilities are so extensive that Microsoft notes it can be used for both destructive operations and quiet espionage activity.
One of GigaWiper’s most notable features is its ability to operate at the physical disk level, allowing it to enumerate drives using Windows Management Instrumentation (WMI) and remove partition references from non-Windows drives. This functionality is identical in both the backdoor component and the standalone wiper, indicating a high degree of sophistication on the part of the threat actor.
The malware’s command-and-control capabilities are equally impressive, with GigaWiper able to communicate with its operators using RabbitMQ and Redis protocols. It can also execute various commands based on received instructions, including running executables, PowerShell scripts, or uploading files to remote servers. Furthermore, the backdoor supports two file-encrypting commands, one of which uses random encryption keys that are never saved.
Microsoft’s analysis suggests that GigaWiper was built by the same developer behind Crucio ransomware, and shares connections with FlockWiper, a malware that emerged in June 2025. The threat actor’s use of this advanced malware highlights the growing trend towards modular, multi-purpose backdoors that can be used for both espionage and destructive operations.
The implications of GigaWiper are significant, as it demonstrates the evolving nature of cyber threats. As threat actors become more sophisticated, their tools will continue to grow in complexity and capability. It is essential for organizations and individuals to remain vigilant and take proactive measures to protect themselves against these emerging threats.
In light of this discovery, we recommend that users take the following steps to protect themselves:
* Ensure that all systems are up-to-date with the latest security patches and software updates.
* Implement robust backdoor detection and prevention measures, such as monitoring for suspicious network activity or anomalous system behavior.
* Regularly back up critical data to prevent loss in the event of a wiper attack.
* Educate employees on the importance of cybersecurity best practices, including avoiding suspicious emails or attachments that may contain malware.
Source: SecurityWeek — 2026-07-10