The GigaWiper malware shows how destructive attacks are becoming more flexible, combining backdoor access, spyware, fake ransomware, and disk-wiping capabilities in a single Windows threat.
Microsoft reports that GigaWiper can wipe physical drives, overwrite the Windows system drive, or encrypt files in a way that leaves no recovery key. This makes the fake ransomware component especially dangerous because it creates the appearance of a ransom incident while the real goal is destruction, not payment.
The malware also includes spying and remote-control features, including screenshots, screen recording, hidden VNC access, process and service management, registry changes, and event-log wiping. In simple terms, attackers can observe the victim, control the system, steal information, and then destroy the machine when they choose.
GigaWiper attempts to blend in by pretending to be OneDrive, creating a scheduled task named OneDrive Update, and using legitimate-looking services such as RabbitMQ, Redis, and MinIO for command, results, and exfiltration traffic. Because naturally, malware also enjoys hiding inside normal business tools, since defenders apparently needed more paperwork.
Organizations should monitor for suspicious scheduled tasks, unusual RabbitMQ or Redis traffic from endpoints, unauthorized VNC activity, strange firewall rules, use of tools such as takeown and icacls against boot files, and attempts to clear Windows event logs.
The key lesson is that destructive malware must be treated differently from ordinary ransomware. When the attacker’s goal is to wipe systems, the only reliable recovery path is fast detection, strong endpoint protection, network containment, and clean offline or immutable backups that cannot be reached from the compromised environment.

Microsoft has taken apart a destructive Windows backdoor it calls GigaWiper. What stands out is how it is built: not one tool but three older destructive programs bolted into one, offered as commands the operator can choose from. Each is a different way to break a machine: wipe the whole disk, overwrite the Windows drive, or run fake "ransomware" that scrambles files with a key it never saves
Source: New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware via The Hacker News — published 09 Jul 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.