CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →
← Back to Daily brief 2026-07-11
NOTABLENATOB2threat

GigaWiper: a Golang backdoor that folds a disk wiper, fake-ransomware encryptor and secure-wipe module into one modular implant

Microsoft dissects GigaWiper, destruction dressed as extortion, driven over RabbitMQ/Redis/MinIO with an 'OneDrive Update' persistence tell

Defender actions

  • Hunt for a scheduled task literally named 'OneDrive Update' running every minute plus at logon, and for a HKCU\\SOFTWARE\\OneDrive\\Environment registry value; neither is created by legitimate OneDrive; confirm the real OneDrive task name/path in your estate as the baseline.
  • In egress/firewall telemetry, surface hosts making outbound RabbitMQ/AMQP, Redis and MinIO/S3-style object-storage connections with no legitimate business reason to speak any of the three, especially all three to the same endpoint.
  • Treat GigaWiper as destruction, not ransomware: because encryption keys are never retained there is no decryption path, prioritise offline, tested backups and recovery drills for internet-exposed Windows critical-infrastructure hosts.

Analysis

Microsoft Threat Intelligence first identified GigaWiper in October 2025 and has now published a code-level analysis of it: a Golang backdoor notable less for any single capability than for its construction, at least three previously separate destructive families folded into one implant as on-demand commands, so an operator can pick the mode of destruction at task time (Microsoft Threat Intelligence, 2026-07-09). The raw-disk wiper command enumerates physical drives over WMI, identifies and spares the Windows installation drive, strips partition metadata from the other drives via DeviceIoControl/IOCTL_DISK_CREATE_DISK, overwrites disk content in 0xA00000-byte chunks (randomising only the first byte of each buffer to dodge naïve all-zero-wipe detections), then forces an immediate reboot. A second command reuses Crucio ransomware code to AES-encrypt files with per-run keys that are never saved and drops no ransom note (destruction wearing an extortion costume) while a third reimplements the C-based FlockWiper in Go for multi-pass secure wiping of the Windows drive. Microsoft ties the families together by code overlap and assesses that the same developer built GigaWiper and Crucio; it withholds actor attribution beyond that lineage. Google's Threat Intelligence Group and Binary Defense track the same activity as BLUERABBIT (Microsoft Threat Intelligence, 2026-07-09; Infosecurity Magazine, 2026-07-10).

Operationally the implant is quieter than its payload. It persists as a scheduled task named OneDrive Update (configured to run roughly every minute and once at startup) and tracks its own execution count in a HKCU\SOFTWARE\OneDrive\Environment registry value, masquerading as Microsoft's sync client. For command-and-control it skips ordinary HTTP: tasking arrives over RabbitMQ/AMQP (a fanout exchange named All for broadcast to every infected client plus a topic exchange for targeted commands) status and output are polled back through a Redis server, and MinIO object storage carries exfiltration, alongside keylogging and screen-capture modules.

Cited evidence

It's not a single, purpose-built tool, but an amalgamation of separate malware families that were folded into GigaWiper as on-demand backdoor commands, giving threat actors the flexibility to choose their mode of destruction

The key and initialization vector (IV) that the malware uses to encrypt files are random and are not saved anywhere

Microsoft Threat Intelligence 2026-07-09

Sources2

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.