DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
TLP:WHITETHREAT ACTOR DOSSIER // GIGAWIPER-IRAN-NEXUSFIRST SEEN: OCT 2025

GIGAWIPER CLUSTER

ALSO KNOWN AS: BLUERABBIT (Binary Defense / Google TIG), CyberAv3ngers-adjacent (IRGC-linked lineage)
FROM:DMZ INTELLIGENCE DESK
ORIGIN:Iran (Iran-nexus; Binary Defense and Google Threat Intelligence Group attribution, medium confidence; IRGC linkage via Crucio malware lineage per CISA)
ATTRIBUTION:STATE-SPONSORED
STATUS:ACTIVE
FIRST OBSERVED:OCT 2025
TECHNICALRESOURCESPERSISTENCESTEALTHIMPACT
TECHNICAL80/100
RESOURCES88/100
PERSISTENCE88/100
STEALTH88/100
IMPACT80/100

Microsoft Threat Intelligence published a July 9, 2026 teardown of GigaWiper, a Golang Windows backdoor that bundles three distinct destruction mechanisms — raw disk wiper, multi-pass OS drive overwrite, and fake ransomware (.candy extension with irrecoverable key discard) — alongside full spyware and remote access capabilities, with the operator selecting the destruction mode post-compromise. Binary Defense and Google TIG track the same malware as BLUERABBIT and attribute it to an Iran-nexus cluster previously responsible for BLUEWIPE and SEWERGOO (June 2025); Crucio code lineage within GigaWiper directly matches a December 2023 CISA advisory on CyberAv3ngers, the IRGC-linked group behind 2023 US/Israeli/UK/Irish water and energy infrastructure intrusions.

Destructive sabotage and espionage against Israeli organizations; geopolitically driven escalation following US-Israel military strikes on Iran (Feb-Mar 2026)

Go-based modular backdoor with 20 numbered operator commands, raw disk overwrite via WMI (Command 1), multi-pass C: drive wipe (Command 12), fake ransomware with .candy extension and discarded keys (Command 3), persistent scheduled task named 'OneDrive Update' (1-minute repeat), spyware/keylogging, C2 over hardcoded IPs, 'GRAT' debug tag shared with FlockWiper toolchain

ISRAEL (CONFIRMED)
CRITICAL INFRASTRUCTURE
GOVERNMENT
ENERGY
WATER

Two hardcoded C2 server IPs (confirmed matching across Microsoft and Binary Defense reports); four file hashes vendor-confirmed identical across GigaWiper and BLUERABBIT analyses; YARA rules and Defender signatures released by Microsoft July 9, 2026; linked malware families: Crucio, FlockWiper, BLUEWIPE, SEWERGOO

FILE DATE: OCT 2025
Initial Destructive Activity (Microsoft observation window)
Microsoft first identified GigaWiper activity in October 2025 while investigating compromised environments that had been wiped with destructive tooling; implant had at least 5 months of operational dwell before broad researcher attention.
FILE DATE: MAR 2026
BLUERABBIT Sightings — Israeli Organization Targeting
Binary Defense (citing Google TIG) independently documents same malware as BLUERABBIT ██████████████████████ of organizations in Israel, linking to the same Iran-nexus cluster behind BLUEWIPE and SEWERGOO.
FILE DATE: JUL 2026
Microsoft Full Disclosure — GigaWiper Technical Teardown
Microsoft publishes full code-level analysis on July 9, 2026 releasing YARA rules, command code mappings, and Defender signatures; vendor-confirms link to Binary Defense BLUERABBIT and IRGC-adjacent Crucio malware lineage.
SHARE BRIEF:✕ Post on Xin Share on LinkedIn