news.mlab.sh
Back to the feed
threat-intel

New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware

High
Image: The Hacker News
Summary

Microsoft has uncovered a sophisticated Windows backdoor, dubbed GigaWiper, that combines destructive capabilities with remote control functionality. GigaWiper operates by bundling three separate tools – a disk wiper, a fake ransomware, and a remote access tool – into a single package. The malware is linked to a group associated with Iran's Islamic Revolutionary Guard Corps, who have been responsible for attacks on critical infrastructure in the US, Israel, the UK, and Ireland. Because it disguises itself as legitimate software and uses existing business services for communication, detection is challenging, requiring specific monitoring of OneDrive tasks, unusual RabbitMQ/Redis traffic, and suspicious use of Windows boot file ownership commands.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.