Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
GigaWiper Malware: A New Threat to Windows Systems

GigaWiper Malware: A New Threat to Windows Systems

Posted on July 9, 2026 By CWS

Microsoft has dissected a new malware threat, GigaWiper, a Windows backdoor with a destructive design. This sophisticated malware combines three older destructive programs, giving attackers a choice of commands to execute, making it a formidable threat.

Destructive Capabilities

GigaWiper provides multiple ways to damage a system. It can wipe the entire disk, overwrite the Windows drive, or simulate ransomware by encrypting files without saving a decryption key. This makes it impossible to recover data without clean backups, emphasizing the importance of early detection.

The malware, also identified as BLUERABBIT by Binary Defense, shares identical file hashes and command servers with GigaWiper, suggesting they are the same threat. Google’s Threat Intelligence Group connects this malware to a group likely linked to Iran, targeting Israeli organizations.

Malicious Functions

Developed in Go, GigaWiper operates on Windows systems and uses specific commands to execute its destructive tasks. One variant erases the disk by overwriting the physical drive and partition table. Another variant, posing as ransomware, encrypts files without offering a recovery option, while the third overwrites the Windows drive with random data.

Furthermore, the malware can spy on affected systems. It captures screenshots, records screen activity, and opens hidden remote sessions for attackers to control the device. It also collects system information, manages processes, and can erase event logs to hide its presence.

Origins and Attribution

Microsoft traces GigaWiper’s code lineage to Crucio and FlockWiper, indicating a single developer’s involvement. Although Microsoft does not specify a nation, the code similarities align with a December 2023 CISA advisory linking Crucio to Iran’s Islamic Revolutionary Guard Corps. Reports suggest this group has previously targeted infrastructure in the US, Israel, and Europe.

The recurring tag “GRAT” in the malware’s code suggests a connection between different tools, hinting at an evolving threat. Microsoft positions GigaWiper as a flexible platform that can spy, steal, or destroy data, complicating detection efforts for defenders.

Defensive Measures

Detecting GigaWiper requires vigilance. Indicators include a recurring “OneDrive Update” task, unexpected RabbitMQ or Redis traffic, and unusual file ownership changes. Microsoft advises activating tamper protection, blocking known command servers, and utilizing advanced endpoint detection solutions.

The Hacker News is seeking further clarification from Microsoft and Binary Defense regarding the malware’s impact and potential victims and will provide updates as information becomes available.

The Hacker News Tags:Binary Defense, BLUERABBIT, cyber attacks, cyber defense, Cybersecurity, disk wiping, fake ransomware, GigaWiper, Iranian hackers, malware detection, Microsoft, OneDrive Update, Spyware, threat intelligence, Windows malware

Post navigation

Previous Post: AI Aids Hacker in Swift 72-Hour AWS Cloud Breach
Next Post: Critical Roundcube XSS Flaws Require Immediate Update

Related Posts

ComicForm and SectorJ149 Hackers Deploy Formbook Malware in Eurasian Cyberattacks ComicForm and SectorJ149 Hackers Deploy Formbook Malware in Eurasian Cyberattacks The Hacker News
300 Servers and €3.5M Seized as Europol Strikes Ransomware Networks Worldwide 300 Servers and €3.5M Seized as Europol Strikes Ransomware Networks Worldwide The Hacker News
Cybercriminals Exploit Remote Monitoring Tools to Infiltrate Logistics and Freight Networks Cybercriminals Exploit Remote Monitoring Tools to Infiltrate Logistics and Freight Networks The Hacker News
Microsoft Shuts Down Malware-Signing Service Linked to Ransomware Microsoft Shuts Down Malware-Signing Service Linked to Ransomware The Hacker News
Enhance Phishing Detection to Prevent Business Risks Enhance Phishing Detection to Prevent Business Risks The Hacker News
n8n Warns of CVSS 10.0 RCE Vulnerability Affecting Self-Hosted and Cloud Versions n8n Warns of CVSS 10.0 RCE Vulnerability Affecting Self-Hosted and Cloud Versions The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI and Security: Key Insights from This Week’s Cyber Threats
  • Iran-Linked Cyberattack Disrupts UK Power Plant for Four Days
  • Windows 11 App Promotes Bing in Major Browsers
  • TikTok Settles $400M U.S. Child Privacy Lawsuit
  • Top Wi-Fi Security Solutions for 2026 Unveiled

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI and Security: Key Insights from This Week’s Cyber Threats
  • Iran-Linked Cyberattack Disrupts UK Power Plant for Four Days
  • Windows 11 App Promotes Bing in Major Browsers
  • TikTok Settles $400M U.S. Child Privacy Lawsuit
  • Top Wi-Fi Security Solutions for 2026 Unveiled

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark