Microsoft Uncovers GigaWiper Backdoor Combining Disk Wiping and Spyware
Microsoft has analyzed a new Windows backdoor called GigaWiper that merges three destructive tools: full disk wiping, Windows drive overwriting, and fake ransomware that scrambles files without saving keys. This modular malware gives operators multiple ways to disrupt or destroy infected machines.
Why it matters
GigaWiper's multi-function destructive capabilities represent a sophisticated threat for incident responders and SOC teams to detect and mitigate.
SOC impact
SOC teams should compare the reported tactics with internal telemetry and hunt for similar activity across identity, endpoint, email, and network logs.
Recommended actions
- Review email, identity, endpoint, and network telemetry for activity matching the reported campaign.
- Search for indicators associated with the described phishing or intrusion techniques.
- Brief analysts and help desk teams on the reported threat to improve detection and response.
Executive Summary
Microsoft has analyzed a new Windows backdoor called GigaWiper that merges three destructive tools: full disk wiping, Windows drive overwriting, and fake ransomware that scrambles files without saving keys. This modular malware gives operators multiple ways to disrupt or destroy infected machines. GigaWiper’s multi-function destructive capabilities represent a sophisticated threat for incident responders and SOC teams to detect and mitigate.
SOC Impact
SOC teams should compare the reported tactics with internal telemetry and hunt for similar activity across identity, endpoint, email, and network logs.
Detection and Hunting Focus
- Review email, identity, endpoint, and network telemetry for activity matching the reported campaign.
- Search for indicators associated with the described phishing or intrusion techniques.
- Brief analysts and help desk teams on the reported threat to improve detection and response.
Why It Matters
GigaWiper’s multi-function destructive capabilities represent a sophisticated threat for incident responders and SOC teams to detect and mitigate.