Skip to content

Windows Backdoor GigaWiper Combines Espionage and Data Destruction

At a Glance: GigaWiper is a modular backdoor with espionage and data destruction capabilities that abuses legitimate enterprise protocols for command and control communication, making it difficult to detect in typical corporate environments.

Microsoft and Binary Defense warn of GigaWiper (also known as BLUERABBIT), a Windows backdoor written in Go that combines espionage functions with three different data deletion mechanisms and disguises itself in the network by imitating the OneDrive service.

GigaWiper unites three different destruction mechanisms in a single platform that attackers can select depending on their target. The first function overwrites the physical hard drive and completely deletes the partition table, preventing data recovery. The second component is based on older malware called Crucio and acts as a fake ransomware: it encrypts data with the .candy extension but intentionally stores no decryption key, making data recovery impossible. The third function selectively overwrites the Windows system drive multiple times with alternating data patterns.

In addition to destructive components, the backdoor features extensive espionage tools: the program continuously records screen contents, takes screenshots, and opens a hidden VNC session for direct remote access. The software also collects system data, manipulates the registry, and deletes Windows event logs to cover its own tracks.

Network concealment is achieved by imitating the OneDrive service with a task named “OneDrive Update” executed every minute in Task Scheduler. For data exchange with control servers, the program uses legitimate enterprise protocols: RabbitMQ for task assignment, Redis for results, and MinIO for data exfiltration. This causes malicious network traffic to blend in with regular traffic in corporate environments that routinely use these tools.

Security analysts attribute GigaWiper to a group with Iranian connections that primarily targets Israeli organizations. Parts of the code show functional links to CyberAv3ngers, which has previously been responsible for attacks on industrial control systems in energy and water supply sectors. Since the backdoor is executed only after a successful network breach, no software patch is available for defense. Early detection relies on the following indicators: a task named “OneDrive Update” executed every minute, unexpected data traffic over RabbitMQ or Redis from normal workstations instead of servers, and processes that assume rights to Windows startup files such as bootmgr or ntoskrnl.exe outside regular maintenance windows.


Source: www.it-daily.net · Published July 12, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: