BLUERABBIT Backdoor Targets Windows Systems with Encryption and Wiping Capabilities
Article Content
- •BLUERABBIT backdoor targets Windows systems with encryption and disk wiping.
- •The malware is linked to Iranian threat actors and primarily affects Israeli organizations.
- •First observed in March 2026, BLUERABBIT employs a full-spectrum intrusion framework.
The BLUERABBIT backdoor, a Golang-based malware, has been identified targeting Windows systems since March 2026. It combines data theft, file encryption, and destructive disk wiping, primarily affecting Israeli entities. The malware is believed to be linked to Iranian threat actors. BLUERABBIT encrypts files with a .candy extension and exfiltrates data to cloud storage controlled by attackers. The attack vector includes remote access and system profiling. Organizations are urged to strengthen their defenses against this sophisticated threat. The current status indicates ongoing investigations and heightened awareness among cybersecurity professionals.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Bluerabbit in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…