Skip to content
ThreatCluster

BLUERABBIT Backdoor Targets Windows Systems with Encryption and Wiping Capabilities

First seen 11 Jun 2026, 22:06 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 12, 2026 at 21:54 UTC
  • BLUERABBIT backdoor targets Windows systems with encryption and disk wiping.
  • The malware is linked to Iranian threat actors and primarily affects Israeli organizations.
  • First observed in March 2026, BLUERABBIT employs a full-spectrum intrusion framework.

The BLUERABBIT backdoor, a Golang-based malware, has been identified targeting Windows systems since March 2026. It combines data theft, file encryption, and destructive disk wiping, primarily affecting Israeli entities. The malware is believed to be linked to Iranian threat actors. BLUERABBIT encrypts files with a .candy extension and exfiltrates data to cloud storage controlled by attackers. The attack vector includes remote access and system profiling. Organizations are urged to strengthen their defenses against this sophisticated threat. The current status indicates ongoing investigations and heightened awareness among cybersecurity professionals.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 102d ago How this analysis works

Timeline

2026-03-15
BLUERABBIT first observed
The BLUERABBIT backdoor was first detected targeting Windows systems, focusing on data theft and destruction.
Gbhackers
2026-06-11
BLUERABBIT reported in multiple articles
Cybersecurity articles detail the capabilities of BLUERABBIT, including file encryption and system wiping.
Cybersecuritynews

More articles in this cluster (2)

Following this threat?

Track Bluerabbit in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed