New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware
Microsoft has uncovered a sophisticated Windows backdoor, dubbed GigaWiper, that combines destructive capabilities with remote control functionality. GigaWiper operates by bundling three separate tools – a disk wiper, a fake ransomware, and a remote access tool – into a single package. The malware is linked to a group associated with Iran's Islamic Revolutionary Guard Corps, who have been responsible for attacks on critical infrastructure in the US, Israel, the UK, and Ireland. Because it disguises itself as legitimate software and uses existing business services for communication, detection is challenging, requiring specific monitoring of OneDrive tasks, unusual RabbitMQ/Redis traffic, and suspicious use of Windows boot file ownership commands.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
