GigaWiper: The "Frankenstein" Malware That Can Destroy Your Infrastructure
Microsoft Threat Intelligence has disclosed GigaWiper, a destructive Windows backdoor assembled from three older malware families into a single modular implant capable of wiping disks, deploying fake ransomware, and giving attackers full remote control of compromised machines.
What GigaWiper Is
Written in Go, GigaWiper gives operators at least 20 numbered commands spanning both espionage and destruction. Three commands are designed to render a machine unrecoverable:
- A raw disk wiper that overwrites the physical drive and partition table.
- Fake ransomware derived from code tracked as Crucio, which encrypts files with a
.candyextension but never saves the decryption key. - A multi-pass wiper rewritten from an earlier tool Microsoft calls FlockWiper.
As Microsoft put it: "when a single implant can watch, steal, or destroy, the tool no longer reveals the goal — the operator decides after they are already inside." Microsoft first observed the destructive activity in October 2025, and the same malware was independently identified by Binary Defense in March 2026 under the name BLUERABBIT, based on matching file hashes and command-and-control servers.
Evasion Techniques
Beyond destruction, GigaWiper takes screenshots, records the display, opens hidden VNC sessions, edits the Windows registry, and wipes event logs. It disguises itself as a OneDrive update by creating a scheduled task that fires every minute, and routes command traffic over RabbitMQ, Redis, and MinIO — legitimate enterprise tools whose traffic blends into normal corporate networks.
Microsoft named no country in its report, but Binary Defense, citing Google's Threat Intelligence Group, ties the malware to a likely Iran-nexus group targeting Israeli organizations. The Crucio ransomware code embedded in GigaWiper carries fingerprints listed in a December 2023 CISA advisory on CyberAv3ngers, a group linked to Iran's Islamic Revolutionary Guard Corps that previously compromised water and energy infrastructure in the United States, Israel, the United Kingdom, and Ireland.
Indicators of Compromise to Watch
The following signals suggest a possible GigaWiper presence in an IT environment:
- A scheduled task named "OneDrive Update" running every minute.
- Unusual RabbitMQ or Redis traffic originating from ordinary desktops rather than application servers.
- Processes using
takeownoricaclson Windows boot files outside a maintenance window. - Unexpected VNC sessions or screen-recording activity on user workstations.
Microsoft recommends enabling tamper protection, cloud-delivered antivirus, and endpoint detection and response in block mode, along with blocking known command-and-control servers.
Why This Matters for Your Business
This disclosure arrives amid a broader wave of Iran-linked wiper activity against Israeli targets through 2025 and 2026, including a March 2026 warning from Israel's National Cyber Directorate. For manufacturing companies running OT/IT systems and SaaS businesses dependent on continuous service availability, the risk of operational downtime, data loss, or reputational damage is real and growing.
Frequently Asked Questions
What is the difference between exposure screening and a full security audit?
Exposure screening analyzes what is visible from the outside without touching client systems, while a vulnerability audit is a deeper, authorized analysis requiring written consent and a defined testing scope.
How long does a standard screening take?
Between 3 and 7 business days, depending on infrastructure size.
Is the report understandable for management, not just IT?
Yes — the report includes a business-level summary for management and a technical layer for the IT team.
How Chors.net Can Help
Chors.net specializes in digital exposure monitoring and vulnerability assessment for manufacturing, technology, and service companies, following a repeatable, documented process: scanning externally visible infrastructure, classifying risks, and delivering a clear, prioritized report. The Continuous Monitoring service detects exactly this type of anomaly — unusual RabbitMQ/Redis traffic or new scheduled tasks — before it escalates into a GigaWiper-scale incident.
Order an exposure report — find out if your infrastructure is visible to attackers before they do.
Sources
- Microsoft Threat Intelligence. GigaWiper: A modular destructive implant. Public threat report, 2026. https://www.microsoft.com/security/blog/threat-intelligence/
- Binary Defense. BLUERABBIT: Destructive wiper activity linked to Iran-nexus actors. Threat advisory, March 2026. https://www.binarydefense.com/resources/threat-research/
- CISA (Cybersecurity and Infrastructure Security Agency). IRGC-linked CyberAv3ngers threat advisory. December 2023. https://www.cisa.gov/news-events/cybersecurity-advisories
- Israel National Cyber Directorate. Public warning on destructive wiper activity. March 2026. https://www.gov.il/en/departments/cyber/
- Google Threat Intelligence Group. Iran-nexus targeting of Israeli organisations — 2025/2026 trends. https://cloud.google.com/security/blog
- Chors.net — Exposure Screening i Continuous Monitoring. https://chors.net