CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2272

As cited

Copy frozen at (site build).

threat intel

GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware

In October 2025, Microsoft Threat Intelligence identified GigaWiper, a Golang-based backdoor that combines command-and-control capabilities with multiple destructive payloads including disk wiping, fake ransomware encryption, and system sabotage. The malware is notable for consolidating code from separate malware families-a standalone wiper, Crucio ransomware, and FlockWiper-into a single modular implant that allows threat actors to select their destruction method on demand. This represents a shift in wiper tactics toward operational efficiency by merging standalone tools into unified platforms that reduce deployment footprint while expanding destructive capabilities.

Why it matters: Organizations and defenders need to identify and contain GigaWiper infections immediately, as the backdoor's multiple destructive modules can render systems and storage unrecoverable; detection and mitigation recommendations are available from Microsoft Defender.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware

Microsoft Threat Intelligence identified a Go based backdoor named GigaWiper in October 2025 that combines wiper, ransomware like encryption, and disk wiping functions. The implant assembles separate malware families into modular commands, letting attackers choose actions such as overwriting physical disks or encrypting files with keys that are not saved. Microsoft provides Defender detections, indicators of compromise, and mitigation guidance to help organizations defend against this threat.

Why it matters: Organizations running Windows systems face potential data loss from GigaWiper’s destructive capabilities and should apply Microsoft Defender detections and review the supplied IOCs.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware

Microsoft Threat Intelligence identified a Go based backdoor named GigaWiper in October 2025 that combines wiper, ransomware like encryption, and disk wiping functions. The implant assembles separate malware families into modular commands, letting attackers choose actions such as overwriting physical disks or encrypting files with keys that are not saved. Microsoft provides Defender detections, indicators of compromise, and mitigation guidance to help organizations defend against this threat.

Why it matters: Organizations running Windows systems face potential data loss from GigaWiper’s destructive capabilities and should apply Microsoft Defender detections and review the supplied IOCs.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary