2026-07-11NOTABLEMicrosoft dissects GigaWiper, destruction dressed as extortion, driven over RabbitMQ/Redis/MinIO with an 'OneDrive Update' persistence tell
Crucio
tool · tool:crucio-ransomware
Ransomware family whose encryption routine Microsoft found reused near-verbatim inside GigaWiper's fake-ransomware destruction command, leading Microsoft to assess a common developer for both (Microsoft, 2026-07-09).
Coverage
1
first 2026-07-11 → last 2026-07-11
Latest activity
2026-07-11
Microsoft dissects GigaWiper, destruction dressed as extortion, driven over RabbitMQ/Redis/MinIO with an…
Peak priority
notable
1 notable
Targets
energy
sectors: energy, public-sector, healthcare
Sources cited
2
2 hosts
Action items (3)
Do-now tasks recorded on the entries about Crucio, newest first. Check the date before acting on an older one.
- Hunt for a scheduled task literally named 'OneDrive Update' running every minute plus at logon, and for a HKCU\\SOFTWARE\\OneDrive\\Environment registry value; neither is created by legitimate OneDrive; confirm the real OneDrive task name/path in your estate as the baseline.2026-07-11Microsoft dissects GigaWiper, destruction dressed…
- In egress/firewall telemetry, surface hosts making outbound RabbitMQ/AMQP, Redis and MinIO/S3-style object-storage connections with no legitimate business reason to speak any of the three, especially all three to the same endpoint.2026-07-11Microsoft dissects GigaWiper, destruction dressed…
- Treat GigaWiper as destruction, not ransomware: because encryption keys are never retained there is no decryption path, prioritise offline, tested backups and recovery drills for internet-exposed Windows critical-infrastructure hosts.2026-07-11Microsoft dissects GigaWiper, destruction dressed…
Defender insights
What each entry about Crucio tells a defender to do, newest first.
Triage
Relationships explore in graph
Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.
has variant
- GigaWiperCrucio-derived fake-ransomware encryptor; Microsoft assesses a common developer
Story timeline
Hunting pivots
ATT&CK techniques (10 across 9 tactics)
10 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- ExecutionScheduled Task/Job: Scheduled Task
- PersistenceScheduled Task/Job: Scheduled Task · Modify Registry
- Privilege EscalationScheduled Task/Job: Scheduled Task
- Defense ImpairmentModify Registry
- Credential AccessInput Capture: Keylogging
- CollectionInput Capture: Keylogging · Screen Capture
- Command and ControlApplication Layer Protocol
- ExfiltrationExfiltration Over Web Service: Exfiltration to Cloud Storage
- ImpactData Destruction · Data Encrypted for Impact · Disk Wipe: Disk Content Wipe · Disk Wipe: Disk Structure Wipe
Execution TA0002
T1053.005Scheduled Task/Job: Scheduled Task×1
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.
Evidence: 2026-07-11/gigawiper-golang-destructive-backdoor-modular-wiper · ATT&CK page ↗
Persistence TA0003
T1053.005Scheduled Task/Job: Scheduled Task×1
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.
Evidence: 2026-07-11/gigawiper-golang-destructive-backdoor-modular-wiper · ATT&CK page ↗
T1112Modify Registry×1
Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
Evidence: 2026-07-11/gigawiper-golang-destructive-backdoor-modular-wiper · ATT&CK page ↗
Privilege Escalation TA0004
T1053.005Scheduled Task/Job: Scheduled Task×1
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.
Evidence: 2026-07-11/gigawiper-golang-destructive-backdoor-modular-wiper · ATT&CK page ↗
Defense Impairment TA0112
T1112Modify Registry×1
Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
Evidence: 2026-07-11/gigawiper-golang-destructive-backdoor-modular-wiper · ATT&CK page ↗
Credential Access TA0006
T1056.001Input Capture: Keylogging×1
Adversaries may log user keystrokes to intercept credentials as the user types them. Keylogging is likely to be used to acquire credentials for new access opportunities when OS Credential Dumping efforts are not effective, and may require an adversary to intercept keystrokes on a system for a substantial period of time before credentials can be successfully captured. In order to increase the likelihood of capturing credentials quickly, an adversary may also perform actions such as clearing browser cookies to force users to reauthenticate to systems.
Evidence: 2026-07-11/gigawiper-golang-destructive-backdoor-modular-wiper · ATT&CK page ↗
Collection TA0009
T1056.001Input Capture: Keylogging×1
Adversaries may log user keystrokes to intercept credentials as the user types them. Keylogging is likely to be used to acquire credentials for new access opportunities when OS Credential Dumping efforts are not effective, and may require an adversary to intercept keystrokes on a system for a substantial period of time before credentials can be successfully captured. In order to increase the likelihood of capturing credentials quickly, an adversary may also perform actions such as clearing browser cookies to force users to reauthenticate to systems.
Evidence: 2026-07-11/gigawiper-golang-destructive-backdoor-modular-wiper · ATT&CK page ↗
T1113Screen Capture×1
Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation. Screen capturing functionality may be included as a feature of a remote access tool used in post-compromise operations. Taking a screenshot is also typically possible through native utilities or API calls, such as <code>CopyFromScreen</code>, <code>xwd</code>, or <code>screencapture</code>.
Evidence: 2026-07-11/gigawiper-golang-destructive-backdoor-modular-wiper · ATT&CK page ↗
Command and Control TA0011
T1071Application Layer Protocol×1
Adversaries may communicate using OSI application layer protocols to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.
Evidence: 2026-07-11/gigawiper-golang-destructive-backdoor-modular-wiper · ATT&CK page ↗
Exfiltration TA0010
T1567.002Exfiltration Over Web Service: Exfiltration to Cloud Storage×1
Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel. Cloud storage services allow for the storage, edit, and retrieval of data from a remote cloud storage server over the Internet.
Evidence: 2026-07-11/gigawiper-golang-destructive-backdoor-modular-wiper · ATT&CK page ↗
Impact TA0040
T1485Data Destruction×1
Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and remote drives. Common operating system file deletion commands such as <code>del</code> and <code>rm</code> often only remove pointers to files without wiping the contents of the files themselves, making the files recoverable by proper forensic methodology. This behavior is distinct from Disk Content Wipe and Disk Structure Wipe because individual files are destroyed rather than sections of a storage disk or the disk's logical structure.
Evidence: 2026-07-11/gigawiper-golang-destructive-backdoor-modular-wiper · ATT&CK page ↗
T1486Data Encrypted for Impact×1
Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.
Evidence: 2026-07-11/gigawiper-golang-destructive-backdoor-modular-wiper · ATT&CK page ↗
T1561.001Disk Wipe: Disk Content Wipe×1
Adversaries may erase the contents of storage devices on specific systems or in large numbers in a network to interrupt availability to system and network resources.
Evidence: 2026-07-11/gigawiper-golang-destructive-backdoor-modular-wiper · ATT&CK page ↗
T1561.002Disk Wipe: Disk Structure Wipe×1
Adversaries may corrupt or wipe the disk data structures on a hard drive necessary to boot a system; targeting specific critical systems or in large numbers in a network to interrupt availability to system and network resources.
Evidence: 2026-07-11/gigawiper-golang-destructive-backdoor-modular-wiper · ATT&CK page ↗
Entries about Crucio (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- infosecurity-magazine.com1 (50%)
- microsoft.com1 (50%)
All cited sources (2)
- infosecurity-magazine.comInfosecurity Magazinehttps://www.infosecurity-magazine.com/news/new-gigawiper-espionage-destructive/
- microsoft.comMicrosoft Threat Intelligencehttps://www.microsoft.com/en-us/security/blog/2026/07/09/gigawiper-anatomy-of-a-destructive-backdoor-assembled-from-multiple-malware/