Security News

Cybersecurity news aggregator

CRITICAL Vulnerabilities SC Media

Microsoft details GigaWiper destructive backdoor assembled from older tools

Microsoft has detailed the GigaWiper backdoor, a modular, post-compromise threat written in Go that combines destructive tools including a raw disk wiper, a fake ransomware module (based on Crucio), and a multi-pass Windows drive wiper. It disguises itself as OneDrive and uses legitimate services like RabbitMQ for command and control, while also providing backdoor capabilities such as screen recording and log manipulation. Early detection and secure, offline backups are crucial for defense, as its destructive actions aim to misdirect defenders by posing as ransomware.
Read Full Article →

Malware Microsoft details GigaWiper destructive backdoor assembled from older tools July 9, 2026 Share By SC Staff (Adobe Stock) The Hacker News reports that Microsoft has detailed a destructive Windows backdoor known as GigaWiper, which is notable for its modular construction, combining three distinct destructive tools into a single, operator-selectable package. This malware is deployed after an attacker has already gained initial access to a system, making early detection and secure, offline backups crucial for defense. GigaWiper, written in Go, operates on Windows and presents operators with numbered commands, three of which are designed for system destruction. These include a raw disk wiper that overwrites the physical drive and partition table, a fake ransomware module (based on Crucio) that encrypts files with a non-recoverable key, and a wiper targeting the Windows drive by overwriting it multiple times. The malware also possesses backdoor capabilities, allowing it to take screenshots, record screen activity, and establish hidden VNC sessions. It collects system details, manages processes, and can manipulate event logs to conceal its presence. GigaWiper disguises itself as OneDrive and uses legitimate services like RabbitMQ, Redis, and MinIO for command and control traffic, making it harder to detect. Microsoft links the fake ransomware code to Crucio and the wiper to FlockWiper, suggesting a single developer. Crucio has been previously associated with Iran-nexus groups targeting Israeli organizations. The tactic of posing as ransomware while performing destructive actions, similar to NotPetya, aims to buy attackers time by misdirecting defenders. Source: The Hacker News SC Staff Related Malware New GoodPersonRAT malware distributed via fake LetsVPN installer SC Staff July 9, 2026 The trojanized installer, identified as Kuailian_win-setup.86.msi, embeds a loader and an encrypted payload alongside the authentic LetsVPN application. Malware Armored Likho APT leverages AI-generated malware and BusySnake Stealer SC Staff July 9, 2026 Armored Likho utilizes a modular and evolving toolkit that includes obfuscated remote access trojans (RATs), the Python-based BusySnake Stealer, and Go2Tunnel for network tunneling. Malware Attackers use Microsoft Teams voice calls to deliver EtherRAT malware SC Staff July 7, 2026 The campaign, detailed by Palo Alto Networks' Unit 42, begins with a phishing email containing a malicious PDF. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Adware You can skip this ad in 5 seconds

Share this article