Loading article…
Google Threat Intelligence Group monitors GigaWiper, a modular backdoor with optional destructive payloads, highlighting evolving cyber‑threat landscape.
Google’s Threat Intelligence Group is now tracking the modular GigaWiper malware, a backdoor that lets attackers choose between disk wiping, fake ransomware or system sabotage after gaining network access【2】. The move signals heightened scrutiny of sophisticated wiper tools that can evade traditional defenses.
At a glance
| At a glance | |
|---|---|
| Entity | Google Threat Intelligence Group |
| Malware | GigaWiper (aka BlueRabbit) |
| Capability | Optional destructive modules (disk wipe, fake ransomware, multi‑pass wiper) |
| Tracking start | October 2025 activity identified |
GigaWiper combines multiple malware families into a single implant, offering roughly 20 command‑and‑control functions such as remote shell, file management and hidden remote desktop sessions【2】. Unlike traditional wipers that execute a single destructive payload, GigaWiper lets operators delay or forego destruction, deploying additional tools first. Microsoft’s threat intel notes three distinct destructive modules: a raw disk overwriter, a fake ransomware that discards encryption keys, and a multi‑pass wiper that repeatedly overwrites files【2】. This flexibility marks a shift from “fire‑and‑forget” attacks to a more controlled, multi‑stage approach.
Security experts warn that the modularity of GigaWiper complicates detection. Researchers recommend monitoring for RabbitMQ and Redis traffic on non‑standard ports, as the backdoor uses these protocols for command delivery—a pattern uncommon in typical enterprise networks【2】. Microsoft also advises enabling tenant‑wide tamper protection, disabling local admin merges, and blocking known C2 infrastructure to reduce exposure【2】. The involvement of Google’s Threat Intelligence Group underscores the broader industry effort to map and contain such evolving threats.
The tracking of GigaWiper by Google highlights the growing complexity of wiper malware, where attackers can tailor destruction to their objectives, challenging defenders to adapt detection and response strategies.
Coverage is mostly measured — 240 of 251 reports stay neutral.
Every Monday — the token unlocks, Fed dates & catalysts set to move crypto and markets this week. So you’re never blindsided.
Free · 3-min read · one-click unsubscribe
AI-assisted synthesis by the TrendWatcher Editorial Desk · sourced from 2 outlets · Jul 13, 2026 · How we report
The feature will be fully removed on August 10, 2026, with new backup folder setup disabled from June 15, 2026.
Version 9.0 adds Live Updates, showing running timers or stopwatches on the status bar, lock screen, and always‑on display.
Google Home Premium and Google Health Premium (formerly Fitbit Premium) are bundled with the AI Pro tier at no extra cost.