New ‘GigaWiper’ Malware Combines Espionage & Destructive Capabilities

Microsoft researchers have identified 'GigaWiper,' a new modular backdoor malware that combines espionage capabilities with destructive wiping and ransomware functions. The tool is built from components of previous malware families and is designed for sophisticated cyber-attacks.
Why it matters
The emergence of unified, multi-purpose malware frameworks represents a significant escalation in the threat landscape for enterprise and government systems.
A new multi-purpose backdoor recently discovered by Microsoft marks a dangerous shift toward unified cyber-attack frameworks.
The backdoor, tracked as GigaWiper, is linked to a malware implant with extensive operational capabilities, allowing cyber threat actors to conduct both quiet espionage activity and destructive wiping operations.
Specifically, in its full version, GigaWiper is equipped with several flavors of wiping functionalities, including file-encrypting ransomware that leaves no way to decrypt the files.
These functionalities were also merged into a single robust backdoor, granting the actor more ways to control and destroy infected systems.
GigaWiper allows threat actors to maintain control over infected systems, execute commands, deploy additional tooling and ultimately trigger one of multiple destructive commands on demand.
In a malware analysis published on July 9 by Microsoft Security, the researchers assessed this new sophisticated tool was created by combining and reimplementing components from at least three previously separate malware families.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in