Microsoft says GigaWiper merges ransomware and disk wipers into one modular Windows backdoor
A Golang “Swiss Army knife” packs encryption, disk overwrite, C2, persistence, and recovery sabotage. Here is the playbook.

Microsoft Threat Intelligence says it has been tracking a newly identified destructive Windows backdoor called GigaWiper. The Redmond team reports the Golang-based implant bundles ransomware-like encryption with multiple wiping and control capabilities, modularized into on-demand commands.
Microsoft Threat Intelligence says a newly identified Windows backdoor called GigaWiper is not just another wiper. Last October, Microsoft’s threat-hunting team first spotted attacks using the Golang-based implant they named GigaWiper, and Redmond now says the tool combines ransomware-like encryption with multiple data-wiping features inside a single modular package.
The key point for decision-makers is the “no decryption” promise. Microsoft’s analysts say GigaWiper encrypts files with randomly generated keys that are never saved, meaning victim organizations will never be able to decrypt those files. In other words, it merges what ransomware teams do, with what wiper operators do, plus additional commands to make the compromised device effectively unrecoverable.
Microsoft describes GigaWiper as a shift in how wiper malware is evolving. Traditionally, wipers are designed purely to destroy rather than extort, because the attacker typically does not need to monetize the encrypted outcome. But Microsoft Threat Intelligence writes that consolidating multiple destructive capabilities into a modular backdoor reflects a notable shift in wiper malware, giving criminals both command-and-control and a menu of destruction options. Microsoft declined to answer The Register’s questions about the scale and scope of GigaWiper attacks, so the immediate executive action is not “how big is it yet,” but “how bad is it when it lands.”
In Microsoft’s account, the analysts uncovered two types of GigaWiper samples in victim environments. Both are unstripped portable executable files written in Golang. One sample is a standalone wiper that operates at the physical disk level, overwriting raw disk content, removing partition metadata, and then rebooting the system using Windows shutdown functionality with restart and zero-delay. That sequence matters because it aims to take away both the data and the operating system’s ability to reliably boot, without relying on file-by-file deletion.
The second sample is where the “modular” label gets teeth. It includes the same disk-wiping functionality, but adds persistence, command-and-control, and a command system that can be triggered remotely. Microsoft says it establishes persistence and sets up C2 communication using RabbitMQ over AMQP for receiving commands from the C2 server, and Redis for updating command status and output. It organizes commands into categories such as “always run” for tasks like continuous screen recording, “manage command” for system management functions, and separate “special command” and “shell command” modes for executing additional functionality.
That command taxonomy translates into real-world attack paths. Microsoft says commands include a standalone wiper, along with one that disables Windows recovery, triggers a blue screen of death (BSOD), and leaves the device unable to boot. Microsoft also says there is a destructive command based largely on Crucio ransomware. That ransomware-style module encrypts files with randomly generated keys that are never saved, preventing decryption. Another command bulk encrypts or decrypts files with AES-256 in Cipher Block Chaining (CBC) mode. A different command uses MinIO Client (mc) to upload stolen files to remote storage, which adds a data theft dimension to the destruction story. Microsoft further lists capabilities that are operationally significant: it runs PowerShell commands, takes screen shots and recordings of the compromised device, collects system information, clears Windows event logs, and allows remote control with keyboard and mouse control.
For executives, the second-order implication is not simply “new malware exists.” It is that tooling has become modular enough to support multiple operational objectives from one implant. Microsoft says GigaWiper combines components from at least three previously separate malware families, including Crucio ransomware, a Go reimplementation of FlockWiper, and a standalone disk wiper. Put together, Microsoft’s conclusion is that functionality was merged into a single robust backdoor, granting the actor more ways to control and destroy infected systems. When one implant can wipe storage, break recovery, encrypt data with no keys saved, exfiltrate via MinIO, and hide its tracks by clearing event logs, incident response becomes broader and harder. You are not only restoring systems. You are also determining what was recorded, what was exfiltrated, what was tampered with, and what guarantees your rebuild will not re-execute the same command set.
For peer organizations, especially those with boards and risk committees focused on cyber resilience, this is a governance issue as much as a technical one. Microsoft’s report underscores how fast adversaries can compress multiple malicious functions into one deployable framework and then drive them through C2 and command categories. Even without clarity on the scale and scope of GigaWiper infections, the strategic stake is straightforward: if your environment is hit by a modular backdoor that can both destroy and extort, your downtime, recovery costs, and potential data exposure may all be triggered by the same breach. The most important question for leaders is whether their tabletop exercises and incident playbooks assume a single outcome, instead of multiple ones combined into a single operational package.
This story's Key Insights and Take-aways are locked.
Create a free account to unlock Executive Actions for one credit.
Register to UnlockAlways free for Executives Club members. Join the Club
More in Entertainment

Taylor Sheridan’s ‘Marshals’ became the season’s most-watched broadcast despite franchise-worst Rotten Tomatoes
The ratings proof is real, but the critics score dipped hard. What it means for networks betting on prestige genre TV.

LEGO locks in Donkey Kong Arcade for August 1, 2026 at $199.99
An 1,367-piece, 18+ interactive cabinet set turns 1981 gameplay into a physical machine, with 21 barrel drops.

Kacey Musgraves drops “Mexico Honey” video July 22, filmed in Mexico, directed by Running Bear
The new “Mexico Honey” clip blends desert romance with a Mexico tribute, and it lands on her Billboard No. 3 album.

