Find notable cyber news and cases, enriched with sources, timelines, and signals.

GigaWiper / BLUERABBIT destructive Windows backdoor activity

Malware Activity
First reported
Last updated
Happening score
H score 31
1 unique sources, 1 articles

Summary

Hide ▲

The GigaWiper / BLUERABBIT malware activity now combines disk wiping, fake ransomware, and spyware backdoor functions on Windows, increasing the chance that one intrusion can monitor, destroy, or irreversibly disable infected machines. The implant is written in Go, masquerades as OneDrive, and can run a OneDrive Update scheduled task while hiding its state in the registry. It also routes command traffic through RabbitMQ, Redis, and MinIO, which can make the activity harder to spot on networks that already use those services.

Related Happenings

HollowGraph Windows malware uses Microsoft 365 calendars for covert C2

Malware Activity
H score15 First: 20.07.2026 15:30 Last: 20.07.2026 15:30 Sources 1

About this happening: HollowGraph is a Windows malware activity that abuses a compromised Microsoft 365 calendar and Microsoft Graph API as covert C2, hiding tasking in far-future *...

GigaWiper modular backdoor with wiping and espionage capabilities

Malware Activity
H score22 First: 10.07.2026 18:30 Last: 10.07.2026 18:30 Sources 1

About this happening: The newly analyzed GigaWiper backdoor combines espionage and destructive wiping functions, giving operators a single implant that can control, sabotage, and erase infe...

TinyRCT backdoor with persistence, exfiltration, and self-deletion

Malware Activity
H score22 First: 26.06.2026 13:30 Last: 26.06.2026 13:30 Sources 1

About this happening: The TinyRCT backdoor appeared in a 2025 intrusion operation, adding stealthy persistent access and control to the attackers' toolkit. It also supports command ex...

USB-spreading clipboard-stealing malware targeting cryptocurrency wallets

Malware Activity
H score27 First: 18.06.2026 19:20 Last: 18.06.2026 19:20 Sources 1

About this happening: A USB-spreading clipboard-stealing malware family is actively stealing seed phrases, private keys, and wallet addresses from Windows victims, putting cryptocurrenc...

SprySOCKS Windows backdoor activity against government organizations

Malware Activity
H score23 First: 16.06.2026 12:00 Last: 16.06.2026 12:00 Sources 1

About this happening: SprySOCKS now has documented Windows variants, WIN_DRV and WIN_PLUS, expanding a toolset first known as a Linux-only backdoor. The activity is tied to govern...

Timeline

  1. 09.07.2026 21:08 2 articles · 13d ago

    Microsoft identifies GigaWiper destructive Windows backdoor

    Initial Disclosure

    Microsoft identified GigaWiper as a destructive Windows backdoor written in Go that combines disk wiping, fake ransomware, and spyware functions. The malware hides as OneDrive, uses a OneDrive Update scheduled task, and shares hashes and command servers with BLUERABBIT, while Microsoft also linked its destructive code to older Crucio and FlockWiper components.

    Show sources