hacker-news · Crawled Jul 9, 2026
New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware
2 IoCs 1 Actors
Read original article ↗
AI Summary
Microsoft has analyzed a destructive Windows backdoor named GigaWiper, which combines disk-wiping, fake ransomware, and spyware capabilities. The malware, written in Go, allows operators to choose from multiple destructive payloads, including full disk wiping, overwriting the Windows drive, and fake encryption with no decryption key. It also includes surveillance features such as screen recording, VNC streaming, and system reconnaissance. The same malware was independently identified as BLUERABBIT by Binary Defense and is linked to an Iran-nexus group targeting Israeli organizations, with ties to prior threats like Crucio and FlockWiper.
AI-extracted · verify before operational use