Microsoft Exposes GigaWiper, a New Malware That Spies on Victims Before Destroying Them
A newly discovered backdoor called GigaWiper quietly watches infected computers for months, then wipes or encrypts everything on command, with no way to recover the data.

Key points
- Microsoft published a technical breakdown of GigaWiper on Thursday, November 2025, naming it as a backdoor first seen in October 2025 intrusions.
- GigaWiper bundles destructive code from three separate malware families, Crucio ransomware, FlockWiper, and a raw disk-wiping routine, into one backdoor program.
- The malware disguises its persistence mechanism as a routine "OneDrive Update" scheduled task.
- Crucio encrypts files with keys that are never saved, making recovery impossible even if a victim pays.
- Microsoft recommends offline backups because no decryption tool can undo this destruction.
Most destructive malware charges in and starts deleting things immediately. GigaWiper waits. It first acts as a remote-access backdoor, giving operators quiet, persistent control over a victim's machine. Then, when they decide the moment is right, it destroys everything.
Microsoft's threat-intelligence team published its analysis on Thursday, detailing a tool first spotted in intrusions dating back to October 2025. The write-up describes GigaWiper as a modular backdoor: a single program whose individual parts can be switched on independently. We first covered Crucio and FlockWiper, the two older families GigaWiper draws from, on 10 July 2026.
How does GigaWiper actually work?
GigaWiper exists in two forms: a stripped-down standalone wiper, or a larger backdoor carrying 20 separate commands. Those commands let operators run PowerShell scripts, manage services and processes, capture screenshots, record displays, and remotely control the infected machine through a VNC-like capability (VNC, or Virtual Network Computing, lets someone operate a computer from afar as if they were sitting in front of it).
The malware plants itself on a Windows computer by creating a scheduled task disguised as a "OneDrive Update." From there it phones home using RabbitMQ and Redis, software tools normally used by businesses to pass data between servers. Here, RabbitMQ carries attack instructions inward and Redis returns command output outward.
The destructive side is where GigaWiper stands apart. Microsoft's researchers found it borrows wiping code from three existing malware families. One command overwrites the physical contents of every disk and erases the partition table (the index a computer uses to find its own files). Another borrows from Crucio ransomware, encrypting files with randomly generated keys that are never stored. A third reimplements FlockWiper, running multiple overwrite passes to make data permanently unrecoverable.
Microsoft confirmed the connections through code analysis, shared execution patterns, function naming, and unique strings. Crucio was the base for command 3; FlockWiper was re-coded in Go for command 12.
Because the Crucio-based encryption discards its own keys, there's nothing to decrypt later. No ransom payment helps.
Should you worry?
If you run IT or security for an organisation, Microsoft's guidance is direct: keep offline backups that malware can't reach, enable endpoint detection and response software (tools that watch for suspicious behaviour in real time), and apply attack-surface reduction controls to limit what programs can do. Microsoft has also published file hashes for Crucio and FlockWiper and a set of command-and-control IP addresses to help defenders spot it.
For ordinary employees, the practical step is the same one that applies to most intrusions: treat unexpected email attachments and links with suspicion. That's almost always how attackers get a first foothold before tools like GigaWiper are ever deployed.
What matters most here is the architecture, not the destruction. Wrapping three proven wreckers inside a patient, modular backdoor gives operators flexibility that a simple wiper never had. Watch for variants that swap in different payloads once the command structure is established.



