GigaWiper combines surveillance with three wiper functions
Microsoft has described a malware family it calls GigaWiper. It offers a broad range of capability, from silent surveillance to full remote control of the victim. What sets it apart is that it includes three destructive wiper functions, all three of which have previously been observed as standalone malware. The analysis suggests older malware has been combined and extended into a robust and versatile backdoor, first observed by Microsoft in 2025. The blog post includes several recommendations for hardening systems against threats of this kind.
What this means for your organisation
A backdoor with built-in wiper functions changes the assumptions behind your resilience planning. With ransomware there is at least a counterparty and a theoretical path back. With destruction there is neither, and recovery rests entirely on your backups. The question then is not whether you take backups, but whether they sit beyond the attacker's reach and whether anyone has tested that they actually restore.
Berigo recommends
- Verify that at least one set of backups is immutable or offline, and not reachable with domain credentials.
- Run a genuine restore test of a critical system, timed, and compare the result with what management believes it to be.
- Limit the number of accounts holding rights that can delete or alter backups.
- Follow the hardening recommendations in Microsoft's analysis, documenting which you have adopted and which you have declined.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch