Microsoft Uncovers GigaWiper Backdoor Combining Disk Wiping and Spyware

Microsoft has analyzed a new Windows backdoor called GigaWiper that merges three destructive tools: full disk wiping, Windows drive overwriting, and fake ransomware that scrambles files without saving keys. This modular malware gives operators multiple ways to disrupt or destroy infected machines.

Why it matters

GigaWiper's multi-function destructive capabilities represent a sophisticated threat for incident responders and SOC teams to detect and mitigate.

SOC impact

SOC teams should compare the reported tactics with internal telemetry and hunt for similar activity across identity, endpoint, email, and network logs.

Recommended actions

  1. Review email, identity, endpoint, and network telemetry for activity matching the reported campaign.
  2. Search for indicators associated with the described phishing or intrusion techniques.
  3. Brief analysts and help desk teams on the reported threat to improve detection and response.

Executive Summary

Microsoft has analyzed a new Windows backdoor called GigaWiper that merges three destructive tools: full disk wiping, Windows drive overwriting, and fake ransomware that scrambles files without saving keys. This modular malware gives operators multiple ways to disrupt or destroy infected machines. GigaWiper’s multi-function destructive capabilities represent a sophisticated threat for incident responders and SOC teams to detect and mitigate.

SOC Impact

SOC teams should compare the reported tactics with internal telemetry and hunt for similar activity across identity, endpoint, email, and network logs.

Detection and Hunting Focus

  • Review email, identity, endpoint, and network telemetry for activity matching the reported campaign.
  • Search for indicators associated with the described phishing or intrusion techniques.
  • Brief analysts and help desk teams on the reported threat to improve detection and response.

Why It Matters

GigaWiper’s multi-function destructive capabilities represent a sophisticated threat for incident responders and SOC teams to detect and mitigate.

Source