Feeds.4Sysops Microsoft Unveils GigaWiper: A Modular Destructive Backdoor for Windows
Article Content
- •GigaWiper is a modular backdoor combining destructive tools and espionage capabilities.
- •It disguises itself as OneDrive and uses legitimate services for command and control.
- •The malware is linked to Iranian threat actors targeting Israeli organizations.
Microsoft has revealed GigaWiper, a destructive Windows backdoor that integrates components from three malware families, including Crucio and FlockWiper. This Golang-based malware is designed for post-initial access attacks, allowing operators to execute commands for system destruction, including raw disk wiping and fake ransomware. GigaWiper disguises itself as OneDrive and utilizes legitimate services for command and control, complicating detection efforts. It can take screenshots, record screen activity, and manipulate event logs to hide its presence. Microsoft links the malware to Iranian threat actors, suggesting a state-sponsored motive targeting Israeli organizations. The malware's modular design enables attackers to switch between espionage and sabotage seamlessly. Early detection and secure backups are critical for defense against this threat.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (18)
Following this threat?
Track Crucio in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…