As cited
Copy frozen at (site build).
threat intel
GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware
In October 2025, Microsoft Threat Intelligence identified GigaWiper, a Golang-based backdoor that combines command-and-control capabilities with multiple destructive payloads including disk wiping, fake ransomware encryption, and system sabotage. The malware is notable for consolidating code from separate malware families-a standalone wiper, Crucio ransomware, and FlockWiper-into a single modular implant that allows threat actors to select their destruction method on demand. This represents a shift in wiper tactics toward operational efficiency by merging standalone tools into unified platforms that reduce deployment footprint while expanding destructive capabilities.
Why it matters: Organizations and defenders need to identify and contain GigaWiper infections immediately, as the backdoor's multiple destructive modules can render systems and storage unrecoverable; detection and mitigation recommendations are available from Microsoft Defender.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware
Microsoft Threat Intelligence identified a Go based backdoor named GigaWiper in October 2025 that combines wiper, ransomware like encryption, and disk wiping functions. The implant assembles separate malware families into modular commands, letting attackers choose actions such as overwriting physical disks or encrypting files with keys that are not saved. Microsoft provides Defender detections, indicators of compromise, and mitigation guidance to help organizations defend against this threat.
Why it matters: Organizations running Windows systems face potential data loss from GigaWiper’s destructive capabilities and should apply Microsoft Defender detections and review the supplied IOCs.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware
Microsoft Threat Intelligence identified a Go based backdoor named GigaWiper in October 2025 that combines wiper, ransomware like encryption, and disk wiping functions. The implant assembles separate malware families into modular commands, letting attackers choose actions such as overwriting physical disks or encrypting files with keys that are not saved. Microsoft provides Defender detections, indicators of compromise, and mitigation guidance to help organizations defend against this threat.
Why it matters: Organizations running Windows systems face potential data loss from GigaWiper’s destructive capabilities and should apply Microsoft Defender detections and review the supplied IOCs.
- Source published
- First seen by Cybersecurity Tracker