Security

GigaWiper Malware: Microsoft Details Destructive Backdoor

3 min read

Summary

Microsoft Threat Intelligence has published a deep analysis of GigaWiper, a Golang-based backdoor that combines command-and-control features with multiple destructive payloads, including disk wiping, fake ransomware, and system sabotage. The research matters because it shows attackers consolidating several malware families into a single modular implant, increasing flexibility while reducing deployment footprint.

Need help with Security?Talk to an Expert

GigaWiper malware: why this matters

Microsoft Threat Intelligence has disclosed GigaWiper, a destructive Golang-based backdoor that blends remote control functionality with several wiping and sabotage techniques. For security teams, this is significant because it reflects a shift from single-purpose wipers to modular destructive platforms that can be adapted during an intrusion.

What’s new in Microsoft’s analysis

Microsoft says GigaWiper is not just a standalone wiper. It is a backdoor assembled from multiple malware families, giving operators several on-demand destructive options.

Key capabilities highlighted

  • Physical disk wiping: GigaWiper can overwrite raw disk content and remove partition metadata, making systems unbootable and data recovery difficult.
  • Fake ransomware behavior: One command borrows from Crucio ransomware, encrypting files with randomly generated keys that are never saved, effectively turning encryption into destruction.
  • FlockWiper-style logic: Another wiping routine reimplements FlockWiper behavior in Golang and adds multi-pass secure wiping.
  • Backdoor and C2 functions: The malware supports command-and-control through RabbitMQ over AMQP and uses Redis to report command output and status.
  • Persistence mechanisms: It creates a scheduled task named OneDrive Update and uses the registry path HKCU\SOFTWARE\OneDrive\Environment to track execution.

Why this is important for defenders

The main takeaway is operational efficiency for attackers. Instead of deploying separate tools for persistence, control, encryption, and wiping, GigaWiper consolidates them into one implant. That can make intrusions harder to detect early and allows threat actors to switch from access to destruction quickly.

For IT administrators and SOC teams, this raises the stakes around:

  • Detecting suspicious scheduled task creation
  • Monitoring registry abuse tied to user persistence
  • Watching outbound connections to unexpected RabbitMQ or Redis infrastructure
  • Investigating signs of raw disk access or partition tampering

Impact on IT admins and security teams

Organizations running Windows environments should treat GigaWiper as a destructive threat, not conventional ransomware. Recovery may be impossible in some scenarios because the malware can target partition structures and use unrecoverable encryption methods.

This also reinforces the need for layered defenses, especially endpoint detection, privileged access controls, network segmentation, and offline backups.

  • Review Microsoft’s published Defender detections and indicators of compromise.
  • Hunt for scheduled tasks named OneDrive Update and unusual changes under the OneDrive-related registry path noted by Microsoft.
  • Monitor for unauthorized AMQP, RabbitMQ, and Redis traffic from endpoints.
  • Validate backup and recovery procedures, including offline or immutable backups.
  • Prioritize incident response playbooks for destructive malware scenarios, not just ransomware containment.

Microsoft’s report is a reminder that destructive malware continues to evolve. GigaWiper shows how attackers are combining backdoor access and multi-stage destruction into a single, efficient toolset.

Need help with Security?

Our experts can help you implement and optimize your Microsoft solutions.

Talk to an Expert

Stay updated on Microsoft technologies

GigaWipermalwareMicrosoft Threat Intelligencedestructive malwareMicrosoft Defender

Related Posts

Security

Microsoft Digital Defense Report 2026: Key Security Insights

Microsoft's 2026 Digital Defense Report highlights how AI and growing system interconnectedness are reshaping both cyberattacks and defense strategies. The report emphasizes that organizations must secure AI, identities, data, and cloud environments together while improving signal correlation across tools to detect modern threats faster.

Security

Government Cyber Risk in 2026: Microsoft’s 5 Priorities

Microsoft says government agencies were the most targeted sector in 2026, accounting for 27% of observed cyber threat activity. The company urges public-sector leaders to focus on five resilience priorities, including faster response, AI security, bidirectional information sharing, and planning for incidents that spread across suppliers and essential services.

Security

Microsoft Ignite 2026 Security Guide: Key Sessions

Microsoft has published its security guide for Microsoft Ignite 2026, highlighting AI-first security themes, a dedicated Security Pre-Day, and technical sessions focused on securing identities, data, devices, clouds, and AI agents. For IT and security teams, the event offers an early look at Microsoft’s roadmap and practical guidance for building an AI-ready security strategy.

Security

CVE-2026-73570: Zimbra Mail Server Exploitation

Microsoft is tracking active exploitation of CVE-2026-73570, an unauthenticated command injection flaw affecting internet-facing Zimbra mail servers with the optional zimbra-snmp package installed and SNMP notifications enabled. The issue can lead to web shell deployment, privilege escalation, mailbox data theft, and persistent remote access, making immediate patching and configuration review critical for administrators.

Security

Phishing Abuses RMM Tools for Persistent Access

Microsoft security researchers observed phishing campaigns in July 2026 that used a legitimate MSP360 RMM installer disguised as meeting invites, PDF updates, and other lures to gain remote access. Attackers then deployed ConnectWise ScreenConnect for redundant persistence, highlighting the need for tighter controls on remote management tools and better detection of unapproved RMM activity.

Security

Azure DevOps Attack Path Exposed in New DART Report

Microsoft’s latest DART cyberattack report shows how a single compromised identity was used to access Azure DevOps, alter pipelines, and harvest Kubernetes credentials. The case highlights how tightly connected identity, DevOps, and cloud environments can let attackers move far beyond source code, making stronger identity and pipeline controls essential.