VMTech
Discuss a project

GigaWiper: backdoor, wiper and fake ransomware in one Windows implant

GigaWiper: backdoor, wiper and fake ransomware in one Windows implant

Colleagues, I’d like to draw your attention to a cybersecurity update: Microsoft has analyzed GigaWiper, a Windows implant that combines ransomware, wiper, and espionage capabilities.

What the threat does:
• wipes the disk or a Windows partition
• imitates ransomware, but with no chance of recovery
• takes screenshots, records the screen, and opens covert VNC access

For cover, it uses a OneDrive Update task, while communication runs through RabbitMQ, Redis, and MinIO. This makes network detection more difficult.

Why it matters: there is no “patch for a vulnerability” here, so early detection, offline backups, tamper protection, and blocking known C2 infrastructure are critical.

Are you already monitoring such signals in your environment?
#cybersecurity #malware #Windows #ThreatIntelligence

GigaWiper: what defenders should monitor

GigaWiper should be treated as both an intrusion and a destructive threat. Because it combines covert access, surveillance and data-wiping behavior, monitoring should correlate endpoint activity, scheduled tasks and network communications rather than depend on a single indicator.

Why GigaWiper is not ordinary ransomware

The implant displays ransomware-like behavior, but the described wiping activity leaves no recovery path through payment. The practical priority is therefore early detection, containment and recoverable offline backups—not preparation for ransom negotiations.

  • It can wipe a disk or Windows partition.
  • It imitates ransomware without offering recovery.
  • It can capture screenshots and record the screen.
  • It can provide covert remote access through VNC.

Signals that need context

GigaWiper reportedly uses a task named OneDrive Update for cover and communicates through RabbitMQ, Redis and MinIO. A single task name or network connection may not provide enough context, so teams should examine combinations of unusual endpoint and network behavior.

  • Review unexpected activity linked to tasks named OneDrive Update.
  • Correlate screen capture behavior with unusual remote access.
  • Investigate unexpected RabbitMQ, Redis or MinIO communications.
  • Block known command-and-control infrastructure when indicators are available.

Practical resilience checklist

The update does not describe a vulnerability that can be resolved with one patch. Defensive preparation should instead focus on detecting suspicious behavior, protecting security controls and maintaining backups that remain available after an endpoint is compromised.

  • Keep offline backups separate from affected Windows systems.
  • Protect monitoring and security controls against tampering.
  • Prioritize alerts that combine endpoint and network signals.
  • Define a containment process for suspected destructive activity.

Frequently asked questions

What is GigaWiper?

GigaWiper is a Windows implant described as combining backdoor access, destructive wiping, surveillance functions and fake ransomware behavior.

Is GigaWiper genuine ransomware?

It imitates ransomware, but the described disk or partition wiping does not provide a recovery option through payment.

Can GigaWiper be stopped with a Windows vulnerability patch?

The summarized update does not identify a single vulnerability patch as the solution. It emphasizes early detection, offline backups, tamper protection and blocking known C2 infrastructure.

Which GigaWiper signals should defenders review?

Relevant signals include unexpected activity involving a OneDrive Update task, screen capture, covert VNC access and unusual communications through RabbitMQ, Redis or MinIO.

Open analytics
On the site 2 views
min read 1 09.07.2026
On Instagram 3 views
On Instagram 1 reach
Instagram

GigaWiper: backdoor, wiper and fake ransomware in one Windows implant

Open the post on Instagram ↗