Security News

Cybersecurity news aggregator

INFO News Dark Reading

GigaWiper Lets Threat Actors Choose Their Own Destructive Attack

  • What: GigaWiper allows threat actors to choose destructive attacks
  • Impact: Cybersecurity tools are being used to enable more customizable and dangerous attacks
Read Full Article →

Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands An Informa TechTarget Publication Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise Newsletter Sign-Up Newsletter Sign-Up Cybersecurity Topics Related Topics Application Security Cybersecurity Careers Cloud Security Cyber Risk Cyberattacks & Data Breaches Cybersecurity Analytics Cybersecurity Operations Data Privacy Endpoint Security ICS/OT Security Identity & Access Mgmt Security Insider Threats IoT Mobile Security Perimeter Physical Security Remote Workforce Threat Intelligence Vulnerabilities & Threats Recent in Cybersecurity Topics Application Security AI Coding: Do Security Risks Outweigh Productivity Gains? AI Coding: Do Security Risks Outweigh Productivity Gains? by Alexander Culafi Jul 10, 2026 7 Min Read Vulnerabilities & Threats Microsoft Reins in RoguePlanet Zero-Day Threat Microsoft Reins in RoguePlanet Zero-Day Threat by Rob Wright Jul 9, 2026 4 Min Read World Related Topics DR Global Middle East & Africa Asia Pacific Latin America Recent in World See All Cybersecurity Operations State IDs for AI Agents: Will Estonia Set a Precedent? State IDs for AI Agents: Will Estonia Set a Precedent? by Nate Nelson Jul 8, 2026 5 Min Read The Edge DR Technology Events Related Topics Upcoming Events Podcasts Webinars SEE ALL Resources Related Topics Resource Library White Papers Reports Webinars Newsletters Podcasts Heard It From a CISO Reporters' Notebook Dark Reading's 20th Videos Dark Reading Polls Partner Perspectives Meet the Editors Advertise With Us About Us Dark Reading Resource Library Cyberattacks & Data Breaches Threat Intelligence Vulnerabilities & Threats Cyber Risk News GigaWiper Lets Threat Actors Choose Their Own Destructive Attack A modular implant borrows from various malware families to combine both backdoor and wiper activities to maximize impact and minimize operational output. Elizabeth Montalbano , Contributing Writer July 13, 2026 4 Min Read Source: MasPix via Alamy Stock Photo A novel modular malware lets attackers choose their own adventure regarding how they want to destroy a targeted system. The malware, described as "a wiper inside a backdoor," combines multiple malware capabilities into a single implant that allows attackers to maximize their impact while minimizing their operational footprint. Researchers initially spotted the malware, dubbed GigaWiper, during "destructive wiper activity" in October 2025 and thought they were looking at a Golang-based backdoor, according to a recent post on the Microsoft Threat Intelligence (MTI) blog. However, upon closer inspection, the researchers realized that GigaWiper combines separate malware families and gives attackers flexibility to choose how they can destroy a system via on-demand backdoor commands once they've established control of the victim network. "GigaWiper [is] a versatile implant that combines robust command-and-control (C2) capabilities with multiple destructive payloads , including disk wiping, fake ransomware, and system-level sabotage," according to the post. Related: Turning the Tables on Email Scammers With 'ScamBuster' Microsoft acknowledged in the post that Google Threat Intelligence Group is also tracking GigaWiper, calling it BlueRabbit. Additionally, a previous report from Binary Defense also observed BlueRabbit, attributing it to an Iran-based threat actor. Microsoft did not attribute the malware to specific threat actors or nations in its post. GigaWiper: Not Your Average Wiper "The consolidation of multiple destructive capabilities into a modular backdoor reflects a notable shift in wiper malware ," according to the MTI post. Wipers are typically used for destructive attacks designed to encrypt or delete systems' data with no option for recovery. "Traditional wipers are fire-and-forget," Denis Calderone, chief technology officer of security firm Suzu Labs, tells Dark Reading. "The attacker gets access, deploys the wiper, detonates it, and destruction is the entire point of the intrusion. GigaWiper flips that. The destruction is optional." Overall, the backdoor supports roughly 20 commands covering activities such as remote shell execution, file management, process control, system reconnaissance, screenshot capture, and hidden remote desktop sessions. All of this is aimed at giving attackers "extensive operational capabilities" that allow a threat actor to control infected systems and deploy additional tooling before launching any disruptive actions, according to the post. Specifically, Microsoft identified three destructive modules in GigaWiper designed to give organizations little chance of recovering the destroyed data and assets. These included a raw disk wiper that overwrites physical disks and destroys partition information; fake ransomware derived from the Crucio ransomware family that encrypts files using random keys that are intentionally discarded, making recovery impossible; and a multipass secure wiper based on FlockWiper that repeatedly overwrites files to hinder forensic recovery. Related: 'GodDamn' Ransomware Uses BYOVD to Smite US Companies Its ability to destroy systems isn't the only modular functionality of the malware, the researchers found. The back-end C2 infrastructure also demonstrates modularity; instead of relying primarily on HTTP or DNS communications, as is typical, operators use RabbitMQ, an Advanced Message Queuing Protocol (AMQP) implementation, to receive commands from the C2 server, and Redis server for updating command status and output. "Overall, these findings show the evolution of the actor's tooling over time," according to the post. "Functionality was merged into a single robust backdoor, granting the actor more ways to control and destroy infected systems." Defending Against Destruction Wiper malware is a fearsome cyber threat for many organizations, given its inherent destructive nature, and attackers often use it to target critical infrastructure, especially in times of conflict. Threat actors recently used the Lotus wiper to target Venezuelan energy firms, and Russian threat actors have extensively used wipers against Ukrainian targets during the ongoing war between the two countries. Related: Vidar Infostealer Hammers SMBs via Malvertising Campaign Because of how devastating wiper attacks can be, security experts advise that organizations try to mitigate such an attack altogether. "Hunt for the pre-destruction phase, because that's where GigaWiper is actually beatable," Calderone observes. He recommends that defenders look for RabbitMQ and Redis traffic on nonstandard ports leaving their environment, "since that's not a protocol stack you see in normal enterprise networks." Another way defenders can avoid such attacks is by hardening networks against GigaWiper and similar malware. To do this, Microsoft recommended that defenders implement the following mitigation steps: turn on tenant-wide tamper protection features to prevent attackers from stopping security services or using antivirus (AV) exclusions; enable DisableLocalAdminMerge on Intune or Microsoft Defender for Endpoint Security Configuration to prevent modification of antivirus exclusions via Group Policy Objects (GPO); and block direct access to known C2 infrastructure where possible, informed by your organization's threat intelligence sources. Additionally, defenders should turn on cloud-delivered protection in their respective AV products to cover rapidly evolving attacker tools and techniques, as cloud-based machine learning protections block a majority of new and unknown threats, the researchers noted. According to Microsoft, organizations should also block executable files from running unless they meet a prevalence, age, or trusted list criterion. About the Author Elizabeth Montalbano Contributing Writer Elizabeth Montalbano is freelance writer, editor, and journalist with 30 years of professional experience and a master's degree from Arizona State University. Her areas of expertise include enterprise technology, cybersecurity, business, and culture. During her long career, Elizabeth has lived and worked as a full-time journalist in Phoenix, San Francisco, and New York City. She specializes in news coverage and analysis, using her years of experience to look at the current state of cybersecurity with a critical gaze. She currently resides in a village on the southwest coast of Portugal, where in her free time she enjoys surfing, hiking with her dogs, growing plants, and playing and performing as a singer and musician. See more from Elizabeth Montalbano Want more Dark Reading stories in your Google search results? Add Us Now More Insights Industry Reports The State of Cloud Security: The Latest Challenges The total economic impactâ„¢ of Snyk How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Access More Research Webinars When AI Becomes an Insider: Rethinking Risk in Critical Infrastructure Governing the Agent; Identity Security in the Age of Autonomous AI Securing the AI Era: Shadow AI, AI Agents, and Why AI Detection and Response Changes Everything Practical Zero Trust Implementation on a Budget in the Age of Mythos Building a Risk Based Vulnerability Management Program More Webinars Editor's Choice Cybersecurity Operations Why Identity Security Is Your Cyber Career Entry Point Why Identity Security Is Your Cyber Career Entry Point by Kristina Beek Jun 30, 2026 Cyberattacks & Data Breaches EdTech Attackers Shift From Schools to Their Software Suppliers EdTech Attackers Shift From Schools to Their Software Suppliers by Arielle Waldman Jun 25, 2026 Want more Dark Reading stories in your Google search results? Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or

Share this article