CyberSecurityBoardThreat Intel · CVEs · Products
Malware

GigaWiper: New Windows Backdoor Combines Disk Wiping, Fake Ransomware, and Spyware

July 9, 2026

Microsoft has dismantled a destructive Windows backdoor named GigaWiper, which combines three older malicious tools into a single platform. The malware, written in Go, offers operators commands to wipe disks, overwrite the Windows drive, or deploy fake ransomware that encrypts files without saving the decryption key, making recovery impossible.

GigaWiper also includes spyware capabilities, such as taking screenshots, recording screens, opening hidden VNC sessions, collecting system details, managing processes, editing the registry, and wiping Windows event logs. It masquerades as OneDrive by creating a scheduled task named ‘OneDrive Update’ and hides its remote-control channel behind a firewall rule named after a legitimate Windows component.

Microsoft traces GigaWiper’s fake-ransomware code to Crucio and its multi-pass wiper to FlockWiper, assessing that the same developer built all three. Crucio was previously linked to CyberAv3ngers, an Iran-nexus group, in a December 2023 CISA advisory. Binary Defense has identified the same malware under the name BLUERABBIT, tying it to an Iran-linked group targeting Israeli organizations.

Defenders are advised to monitor for a OneDrive Update scheduled task running every minute, RabbitMQ or Redis traffic from desktops, and processes using takeown and icacls on Windows boot files. Microsoft recommends enabling tamper protection, blocking known command servers (185.182.193[.]21 and 212.8.248[.]104), and using endpoint detection in block mode.

CVEs: CVE-2026-55200, CVE-2026-46817

Attack groups: CyberAv3ngers, Iran-nexus group

Malware: GigaWiper, BLUERABBIT, Crucio, FlockWiper

Companies: Microsoft, Binary Defense, Google

Products: OneDrive, RabbitMQ, Redis, MinIO