New Destructive Malware "GigaWiper" Targets Windows Systems with Irreversible Damage
Microsoft has identified a new Windows threat, GigaWiper, a highly destructive malware designed to erase disks, corrupt files beyond recovery, and disrupt operations. First observed in October 2025, the malware marks a shift from data theft to outright system destruction, combining multiple attack methods into a single tool.
GigaWiper operates as a Golang-based backdoor, allowing attackers to persist on infected systems, collect data, and execute destructive commands on demand. Unlike traditional ransomware, it offers no recovery path files encrypted with the .candy extension are permanently lost, and disk-wiping functions target critical system structures, including boot files and partition tables. The malware also clears Windows event logs, complicating incident response efforts.
The threat leverages RabbitMQ for command-and-control (C2) communication and Redis for status updates, enabling operators to coordinate attacks across multiple devices. Persistence is maintained through a scheduled task disguised as a "OneDrive Update," blending into normal system activity.
Key capabilities include:
- Multi-pass disk wiping (targeting physical drives and Windows installations)
- Irreversible file encryption (no ransom demand or decryption key)
- Remote control, screen capture, and system discovery
- Boot disruption (deleting recovery and kernel files)
Microsoft’s analysis links GigaWiper to known malware families, including Crucio and FlockWiper, suggesting modular development. Indicators of compromise (IoCs) include multiple SHA-256 hashes and C2 IP addresses (185.182.193[.]21, 212.8.248[.]104).
The malware’s flexibility ranging from covert surveillance to full system destruction highlights the growing threat of wiper malware, which prioritizes disruption over financial gain. Organizations are advised to treat GigaWiper infections as business continuity emergencies, emphasizing isolation, backup validation, and rapid detection to mitigate damage.
Source: https://cybersecuritynews.com/gigawiper-malware-attacking-windows-systems/
Microsoft Threat Intelligence cybersecurity rating report: https://www.rankiteo.com/company/microsoft-threat-intelligence
"id": "MIC1783679126",
"linkid": "microsoft-threat-intelligence",
"type": "Cyber Attack",
"date": "10/2025",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'type': 'Organizations (unspecified)'}],
'attack_vector': ['Backdoor',
"Scheduled Task (disguised as 'OneDrive Update')"],
'data_breach': {'data_encryption': 'Yes (irreversible, .candy extension)',
'type_of_data_compromised': 'Files (irreversibly encrypted), '
'system logs (cleared)'},
'date_detected': '2025-10',
'description': 'Microsoft has identified a new Windows threat, GigaWiper, a '
'highly destructive malware designed to erase disks, corrupt '
'files beyond recovery, and disrupt operations. The malware '
'combines multiple attack methods into a single tool, '
'operating as a Golang-based backdoor with no recovery path '
'for encrypted files (marked with the .candy extension). It '
'targets critical system structures, including boot files and '
'partition tables, and clears Windows event logs to complicate '
'incident response.',
'impact': {'data_compromised': 'Files encrypted irreversibly, disk wiping',
'operational_impact': 'Business continuity emergency, potential '
'permanent data loss',
'systems_affected': 'Windows systems'},
'initial_access_broker': {'backdoors_established': 'Golang-based backdoor'},
'lessons_learned': 'Growing threat of wiper malware prioritizing disruption '
'over financial gain; need for robust backup validation '
'and rapid detection.',
'motivation': 'Disruption (system destruction)',
'post_incident_analysis': {'root_causes': 'Modular development (linked to '
'Crucio and FlockWiper malware '
'families), use of RabbitMQ/Redis '
'for C2 communication, persistence '
'via scheduled tasks.'},
'ransomware': {'data_encryption': 'Yes (irreversible)',
'ransom_demanded': 'No'},
'recommendations': 'Treat GigaWiper infections as business continuity '
'emergencies; emphasize isolation, backup validation, and '
'rapid detection to mitigate damage.',
'references': [{'source': 'Microsoft'}],
'response': {'containment_measures': 'Isolation, backup validation, rapid '
'detection'},
'title': "New Destructive Malware 'GigaWiper' Targets Windows Systems with "
'Irreversible Damage',
'type': 'Wiper Malware'}