Briefing

Microsoft Dissects GigaWiper: A Modular Windows Backdoor Built from Older Destructive Programs

security
by [email protected] (The Hacker News) ·

Review Windows security logs for signs of GigaWiper‑like disk wiping, drive overwriting, or ransomware‑style file scrambling.

What to do now

Review Windows security logs for signs of GigaWiper‑like disk wiping, drive overwriting, or ransomware‑style file scrambling.

Summary

Microsoft has analyzed the destructive Windows backdoor known as GigaWiper, revealing that it is not a single tool but a collection of three older destructive programs combined into one command‑based system. The backdoor offers operators the ability to wipe an entire disk, overwrite the Windows drive, or run a fake ransomware that scrambles files with a key it never saves. Each command is selectable by the operator, allowing for flexible destructive actions. The modular design increases the threat’s complexity and makes detection more difficult. The analysis highlights the importance of monitoring for signs of disk wiping, drive overwriting, and ransomware‑like file scrambling in Windows environments.

Key changes

  • GigaWiper is composed of three older destructive programs
  • Offers disk wipe, drive overwrite, and fake ransomware options
  • Operator selects commands via a command interface
  • Modular design increases detection difficulty
  • Analysis underscores need for monitoring destructive activity

Affects

enterprise

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting