SUBJECT PROFILE
Microsoft Threat Intelligence published a July 9, 2026 teardown of GigaWiper, a Golang Windows backdoor that bundles three distinct destruction mechanisms — raw disk wiper, multi-pass OS drive overwrite, and fake ransomware (.candy extension with irrecoverable key discard) — alongside full spyware and remote access capabilities, with the operator selecting the destruction mode post-compromise. Binary Defense and Google TIG track the same malware as BLUERABBIT and attribute it to an Iran-nexus cluster previously responsible for BLUEWIPE and SEWERGOO (June 2025); Crucio code lineage within GigaWiper directly matches a December 2023 CISA advisory on CyberAv3ngers, the IRGC-linked group behind 2023 US/Israeli/UK/Irish water and energy infrastructure intrusions.
Destructive sabotage and espionage against Israeli organizations; geopolitically driven escalation following US-Israel military strikes on Iran (Feb-Mar 2026)
OPERATIONAL HISTORY
Go-based modular backdoor with 20 numbered operator commands, raw disk overwrite via WMI (Command 1), multi-pass C: drive wipe (Command 12), fake ransomware with .candy extension and discarded keys (Command 3), persistent scheduled task named 'OneDrive Update' (1-minute repeat), spyware/keylogging, C2 over hardcoded IPs, 'GRAT' debug tag shared with FlockWiper toolchain
KNOWN INFRASTRUCTURE
Two hardcoded C2 server IPs (confirmed matching across Microsoft and Binary Defense reports); four file hashes vendor-confirmed identical across GigaWiper and BLUERABBIT analyses; YARA rules and Defender signatures released by Microsoft July 9, 2026; linked malware families: Crucio, FlockWiper, BLUEWIPE, SEWERGOO