Microsoft Pulls Apart 'GigaWiper', a Windows Backdoor That's Really Three Old Wreckers in a Trench Coat
The malware lets its operator pick how to trash a machine: wipe the disk, kill the Windows drive, or fake a ransomware attack with a key that's thrown away.

Key points
- Microsoft has analysed a destructive Windows backdoor it calls GigaWiper, which bundles three older wrecking tools into a single program.
- The malware lets its operator pick between wiping the entire disk, overwriting only the Windows drive, or running fake ransomware that scrambles files with a key it never saves.
- Unlike normal ransomware, files hit by GigaWiper's fake-encryption mode cannot be recovered even if a victim pays.
- The design is modular, meaning the person running the attack chooses which flavour of destruction to launch at the moment of use.
Microsoft has taken apart a Windows backdoor, malicious software that gives a remote operator a way in, and given it a name: GigaWiper.
What makes it worth your attention is not that it destroys machines. It's how it's assembled.
GigaWiper is not one tool. It's three older destructive programs stitched into a single backdoor, with each offered as a command the operator can issue from wherever they're sitting.
What can GigaWiper actually do to a computer?
It offers three destruction modes, and the attacker picks which one to fire.
The first wipes the whole disk. Every attached drive gets overwritten, the computer won't boot, and the data is gone.
The second is narrower: it overwrites only the drive holding Windows. Secondary storage might survive; the machine itself doesn't.
The third is the sneaky one. It behaves like ransomware, the kind of attack where criminals scramble your files and demand payment for the key to unscramble them. Except GigaWiper generates that scrambling key, uses it once, and discards it. Paying does nothing.
This pattern has a name. It's called a wiper dressed as ransomware, and it's been seen in attacks aimed at Ukraine, where destruction was the goal and the ransom note was cover.
Why does the design matter?
Because it shows how modern destructive malware is being written.
Older wipers did one thing. GigaWiper's author took code from several existing families, wrapped them in a common shell, and exposed each as a selectable command. The operator decides on the day whether to nuke the whole disk, take out just Windows, or trigger the fake-ransomware routine.
For defenders, one sample can look like three different attacks depending on which command was sent. Microsoft's writeup, as reported by The Hacker News, treats the modular structure as the notable finding, not any single wrecking technique inside it.
This is a familiar pattern from ordinary crimeware. Banking trojans and remote-access tools have shipped as pluggable toolkits for years. Destructive malware is now catching up.
We first covered GigaWiper on 9 July 2026, and our earlier reporting on how a Chinese hacking group quietly expanded its own backdoor toolkit last month shows the same modular thinking spreading across threat actors.
Should ordinary people be worried?
Not in the sense that GigaWiper is coming for a home laptop tomorrow. Tools like this are aimed at organisations: companies, hospitals, government offices, utilities.
The practical lesson is the same one that's been true for a decade. If your files only exist on the machine in front of you, a bad afternoon can erase all of them. Backups kept physically separate and tested occasionally are the difference between an inconvenience and a catastrophe.
For businesses, the wiper-in-ransomware-clothing threat is worse than normal ransomware. You cannot negotiate your way out. If GigaWiper's third mode runs on your file servers, the files are gone. Recovery means backups or nothing.
Microsoft has not tied GigaWiper to a specific group or campaign as of writing. The public detail covers the malware itself, not the hands using it. That attribution gap is the thing to watch: a modular, multi-mode wrecking tool sitting unattributed is a live question about who built it and why.



