Microsoft said its threat-hunting team identified a Windows backdoor named GigaWiper that combines data-wiping functions with ransomware capabilities.
Microsoft said its threat-hunting team identified a Windows backdoor named GigaWiper that combines data-wiping functions with ransomware capabilities. The backdoor was first spotted in October by the Redmond threat-hunting team. Microsoft's Threat Intelligence blog described two types of GigaWiper samples found in victim environments, both written in Golang as unstripped portable executable files. One sample operates at the physical disk level, overwriting raw disk content, removing partition metadata, and then rebooting the system using Windows shutdown functionality with restart and zero delay. The second sample includes the same disk-wiping functionality but also establishes persistence and communicates with a command‑and‑control server using RabbitMQ over AMQP and Redis for command status. Commands are organized into categories such as "always run" for continuous screen recording, "manage command" for system management, and "special" or "shell" modes for additional functions. The backdoor includes a standalone wiper command, a command that disables Windows recovery, triggers a blue screen of death, and prevents booting. It also implements a destructive command based on Crucio ransomware, encrypting files with randomly generated keys that are never saved, making decryption impossible. Additional commands bulk encrypt or decrypt files using AES‑256 in CBC mode and use the MinIO client to upload stolen files to remote storage. The malware runs PowerShell commands, captures screenshots and recordings, collects system information, clears Windows event logs, and provides remote keyboard and mouse control. Microsoft declined to answer The Register's questions about the scale and scope of the attacks.
- Publisher
- theregister
- Reliability
- high
- Published
- 7/11/2026, 10:00:36 AM
- Retrieved
- 7/11/2026, 10:00:36 AM
- Relevance
- 80%
- Confidence
- 85%

