DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
TLP:WHITETHREAT ACTOR DOSSIER // CYBERAV3NGERS-GIGAWIPERFIRST SEEN: OCT 2025

CYBERAV3NGERS (GigaWiper/BLUERABBIT Cluster)

ALSO KNOWN AS: BLUERABBIT (Binary Defense/Google GTIG), GigaWiper Cluster, Handala Hack (parallel Iran-nexus group)
FROM:DMZ INTELLIGENCE DESK
ORIGIN:Iran (IRGC-linked; Crucio code fingerprint matches December 2023 CISA CyberAv3ngers advisory)
ATTRIBUTION:STATE-SPONSORED
STATUS:ACTIVE
FIRST OBSERVED:OCT 2025
TECHNICALRESOURCESPERSISTENCESTEALTHIMPACT
TECHNICAL80/100
RESOURCES88/100
PERSISTENCE88/100
STEALTH88/100
IMPACT80/100

Microsoft Threat Intelligence published a detailed teardown of GigaWiper on July 9, 2026, a Golang Windows backdoor attributed by Binary Defense and Google's Threat Intelligence Group to a likely Iran-nexus cluster (overlapping with CyberAv3ngers based on shared Crucio code fingerprints). GigaWiper is uniquely dangerous as a single implant combining espionage and three distinct operator-selectable destruction mechanisms: raw disk wipe via WMI, multi-pass Windows drive overwrite, and a fake ransomware module (.candy extension) that encrypts files while discarding keys, making recovery impossible. The malware masquerades as Microsoft OneDrive via a scheduled task and registry key, using legitimate services RabbitMQ, Redis, and MinIO for C2 to blend into normal network traffic.

Destructive sabotage and espionage targeting Israeli organizations; retaliatory cyber operations post-Operation Epic Fury

T1485 (Data Destruction - disk wipe), T1486 (fake ransomware, no recovery), T1113 (Screen Capture), T1021.005 (VNC), T1070.001 (Clear Windows Event Logs), T1053 (Scheduled Task - OneDrive Update masquerade), T1112 (Registry Modification), T1071 (Application Layer Protocol - RabbitMQ/Redis/MinIO C2), BYOB destruction framework with 20-command numbered protocol, Crucio-derived fake ransomware module

ISRAEL (PRIMARY)
ENERGY
WATER INFRASTRUCTURE
CRITICAL INFRASTRUCTURE (US, UK, IRELAND - HISTORICAL)

Go-language implant tracked as GigaWiper (Microsoft) / BLUERABBIT (Binary Defense/Google GTIG); C2 via RabbitMQ, Redis, MinIO legitimate business services; persistence via HKCU\SOFTWARE\OneDrive\Environment registry key and 'OneDrive Update' scheduled task; firewall rule masquerading as 'Microsoft.Windows.CloudExperienceHost'; shared C2 IPs confirmed across GigaWiper and BLUERABBIT samples; Microsoft released YARA rules and Defender signatures

FILE DATE: OCT 2025
BLUERABBIT/GigaWiper Initial Deployment
Microsoft first observed destructive wiping activity in compromised Israeli organization environments using the GigaWiper implant, with Binary Defense/Google GTIG separately tracking the same toolset as BLUERABBIT targeting Israeli organizations from March 2026.
FILE DATE: MAR 2026
Post-Operation Epic Fury Surge
Iranian wiper activity against Israeli and Western targets surged following U.S.-Israel ███████████████████ Iran (Operation Epic Fury, Feb 28, 2026); Israel's National Cyber Directorate issued warnings of escalating Iranian wiper campaigns.
SHARE BRIEF:✕ Post on Xin Share on LinkedIn