TechBriefe
Tech Briefing

New Destructive Backdoor Blurs Lines Between Spyware and Wiper Attacks

Sofia Petrescu 20.07.2026

The Dual Threat of GigaWiper

Microsoft has issued a warning to cybersecurity professionals regarding a sophisticated new backdoor. This threat, dubbed GigaWiper, was first detected in October 2023. It uniquely combines remote control features with destructive disk-wiping capabilities, posing a significant risk to targeted systems.

GigaWiper is a Golang-based implant. Its design allows for both espionage and immediate data destruction. This dual functionality makes it a particularly dangerous tool for attackers. It can gather intelligence before completely wiping a system clean.

How Does GigaWiper Operate?

The malware's ability to operate as both a spy tool and a destructive wiper is concerning. This blurs the traditional distinctions between different types of cyberattacks. Organizations face a more complex threat landscape with such hybrid tools.

What Are the Implications for Cybersecurity?

GigaWiper provides attackers with extensive remote administration powers. This includes the ability to execute commands and manipulate files. Crucially, it also features multiple methods for erasing data from hard drives. This ensures maximum damage upon activation.

Its modular design allows for flexible deployment and customization. Attackers can tailor its functions to specific targets. This adaptability makes it a potent weapon in advanced persistent threat campaigns.

# What is GigaWiper?

The emergence of GigaWiper highlights an evolving threat. Defenders must now prepare for attacks that combine stealth with sudden, irreversible damage. Traditional defenses might struggle against such multifaceted threats.

Organizations need robust detection and response strategies. These must account for malware that can switch roles from surveillance to destruction. Proactive threat intelligence is more critical than ever.

# When was GigaWiper first observed?

GigaWiper is a new type of malware identified by Microsoft. It is a Golang-based backdoor that can both spy on systems and completely wipe their data, blurring the lines between espionage and destructive attacks.

# Why is GigaWiper considered a significant threat?

Microsoft Threat Intelligence first observed GigaWiper in intrusions that occurred in October 2023. This indicates it is a relatively new but active threat.

GigaWiper is a significant threat because it combines remote administration and data-wiping capabilities. This allows attackers to conduct espionage and then destroy evidence or cripple systems, making it a highly versatile and dangerous tool.

Share:

More stories: