Microsoft has identified GigaWiper, a sophisticated Windows backdoor that grants attackers remote control over infected systems before executing destructive commands to permanently wipe data or encrypt files.
Key Points
- GigaWiper combines code from three older malware families, including Crucio ransomware and FlockWiper, into a single, modular backdoor.
- The malware maintains persistence by creating a scheduled task disguised as a "OneDrive Update" that runs at system startup.
- Attackers can remotely execute 20 different commands, including screen recording, registry modification, and the ability to overwrite physical drive partitions.
- The encryption function mimics ransomware but lacks a recovery mechanism, as randomly generated keys are never saved by the operators.
- Microsoft Defender now includes specific detections for GigaWiper, and the company advises enabling cloud-delivered protection and endpoint detection in block mode.