HomeSecurityGigaWiper: New Threat - Disk Wiping, Fake Ransomware and Spyware

GigaWiper: New Threat – Disk Wiping, Fake Ransomware and Spyware

Microsoft has revealed a new and particularly dangerous threat to Windows that stands out not only for its capabilities, but also for the way it is designed. The malware, called GigaWiper , is not a simple data destruction tool , but a comprehensive attack platform that combines cyberespionage, remote control, and total computer destruction functions

Article Image: New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware

According to Microsoft, GigaWiper integrates three different destruction tools into a single application, allowing attackers to choose the method that best serves their purpose each time. This approach reflects a new trend in cybercrime, where the same malware can be used for both espionage and sabotage.

Three different ways to destroy a system

GigaWiper is developed in the Go (Golang) and runs exclusively on Windows. Rather than being limited to a single attack technique, it features multiple commands that are triggered by its operator.

The first option involves erasing the physical storage drive. The malware directly overwrites the data on the drive and corrupts the partition table, rendering the operating system unbootable and significantly hindering any recovery attempt.

See also: AI Ransomware Abuses Chromium API on Windows and Android

The second method resembles a ransomware attack. Files are encrypted, given a new extension, and even the desktop image is changed with a threatening message. However, unlike classic ransomware, there is no ransom demand nor is the decryption key stored. In other words, the data is permanently lost and the process is purely destructive.

The third technique targets the Windows installation drive exclusively, repeatedly overwriting its data with different patterns to make system recovery impossible.

There is no patch – prevention is the only defense

Unlike a security flaw that can be fixed through a software update, GigaWiper is a malicious program that is activated only after the perpetrators gain access to the computer.

This means there is no Windows update that will directly neutralize the threat. Microsoft points out that the best defense is early detection of suspicious activity, using modern endpoint protection (EDR) solutions, and maintaining up-to-date offline backupsso that data can be restored in the event of an attack.

The same malware also appears as BLUERABBIT

Interestingly, the same files have also been detected by the company Binary Defense, which lists them under a different name, BLUERABBIT.

The two companies published the same hashes and command and control servers, which reinforces the assumption that this is the same malware family. According to information cited by Binary Defense from Google's Threat Intelligence team, the attacks may be linked to a group that likely acts in favor of Iranian interests and has targeted Israeli organizations. Microsoft, however, avoids officially attributing responsibility to a specific state.

GigaWiper - SecNews.gr

Spying before the disaster

Data erasure is only part of GigaWiper's capabilities. The malware can operate as a backdoor, allowing attackers to monitor every user activity without being noticed.

Among other things, it can take screenshots, collect system information, manage processes and services, modify the Windows Registry, and delete event logs to eliminate traces of the attack.

At the same time, it has the ability to remotely control via a hidden VNC connection, allowing the perpetrator to view the computer screen in real time, use the keyboard and mouse, and execute commands as if they were in front of the system.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Microsoft also identified inactive code snippets that point to keylogger and additional data destruction tools, suggesting that the platform is still evolving.

See also: New Windows Backdoor BITSLOTH exploits BITS for covert communication

Hiding techniques and use of legal services

To avoid detection, GigaWiper disguises itself as a OneDrive service. It creates a scheduled task called OneDrive Updatethat runs every minute, while storing presence information in the Windows registry.

Even more worrying is the fact that it uses legitimate business services, such as RabbitMQ, Redis, and MinIO, to exchange commands and transfer data. This way, the network traffic looks normal and is much harder to separate from the normal operation of an organization.

Link to past attacks

Microsoft believes that GigaWiper is based on pre-existing tools such as Crucio and FlockWiper, which appear to have been created by the same developer or development team.

Crucio has previously been linked to the CyberAv3ngers, which has been accused of attacks on critical infrastructure, including water and energy networks in the United States, Israel, and other countries. While Microsoft has not officially confirmed this connection, technical evidence suggests that the new malware is part of a broader family of attack tools.

GigaWiper: New Threat - Disk Wiping, Fake Ransomware and Spyware

Microsoft's recommendations for organizations

The company urges system administrators to enable Tamper Protection , leverage Microsoft Defender's cloud protection capabilities, and operate Endpoint Detection and Response systems in lockdown mode.

At the same time, it is recommended to block known command servers, monitor suspicious tasks such as the fake "OneDrive Update", as well as investigate unexpected use of tools such as takeown and icacls, which can be used to gain control of critical operating system files.

See also: Hackers exploit legitimate sites to distribute BadSpace Windows Backdoor

The GigaWiper case demonstrates that modern cyberattacks are no longer limited to data theft or ransom demands. Attackers are developing increasingly sophisticated platforms, capable of spying, remaining invisible for long periods of time, and, when they decide to do so, completely destroying a system in a matter of minutes. For businesses and organizations, having robust detection mechanisms and reliable offline backups is now a prerequisite for dealing with such threats.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS