What would happen to your establishment if its critical systems were wiped out today? That's the chilling reality posed by GigaWiper, a malware tool that can bypass traditional cybersecurity measures. Learn more about it here.
What Is the GigaWiper Malware?
GigaWiper refers to a sophisticated and destructive backdoor that combines long-term cyber espionage capabilities with irreversible data destruction.
According to cybersecurity research from Microsoft Threat Intelligence and reports from Binary Defense (which tracks the malware as BlueRabbit), the malware may have come from nation-state threat actors in the Middle East.
Code embedded in GigaWiper matches tools previously documented by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and attributed to CyberAv3ngers, which is a threat group officially linked to Iran's Islamic Revolutionary Guard Corps (IRGC).
The Mechanics Behind GigaWiper
Let’s explore how threat actors might use GigaWiper to breach your digital systems.
Phase 1: Infiltration and Camouflage
Criminals deploy the Go-based backdoor into your network, typically through unpatched system vulnerabilities or via compromised user credentials. It cleverly hides inside a scheduled task named "OneDrive Update" that runs every minute. This persistence keeps the threat active even when you reboot your systems.
Phase 2: Silent Surveillance
Attackers might not strike immediately and make themselves known. The backdoor can use custom, numbered commands to take over and quietly capture screenshots, record screens in real time, and even learn about your system inventory.
Phase 3: The Final Sabotage
When the time comes to execute, threat actors have the following options:
- Raw disk wiping: The malware directly overwrites physical disks and deletes partition metadata.
- Fake ransomware: Attackers might use code based on the Crucio family to encrypt files with randomly generated keys. Since they don't save the keys, recovery is entirely impossible.
- Secure overwrites: It permanently erases the Windows installation drive by overwriting its data multiple times.
Protecting Your Critical Assets From GigaWiper Destruction
With traditional forms of ransomware deployment, attackers want victims to believe recovery is possible after payment. GigaWiper focuses on disruption by corrupting or deleting data to leave systems unusable. There may be no reliable decryption path because the goal is destruction, not negotiation.
Why wait for this threat to cripple your business? Consider the following preventive measures:
- Implement tenant-wide tamper protection: This safeguard helps ensure that critical security settings and antivirus configurations remain unaltered, even when an attacker gains limited access.
- Block command-and-control (C2) infrastructure: Leverage advanced threat intelligence to identify and block traffic to malicious C2 servers. These servers enable attackers to communicate with compromised systems, and cutting off the connection can disrupt the attack chain.
- Prioritize cloud-delivered protection: Cloud-based programs allow for real-time updates and detection of advanced malware before it reaches your systems. It's a proactive measure that adds agility and scalability to your security posture.
Threat actors built GigaWiper on a multi-malware framework, making it adaptable and highly dangerous. With cyber threats only becoming more and more sophisticated by the day, businesses should stay vigilant and adopt proactive security measures.


