GigaWiper (BLUERABBIT) — Go-Based Modular Backdoor Bundles Raw Disk Wiper, Crucio-Derived Fake Ransomware, and FlockWiper Drive Overwriter Behind Espionage Tooling
GigaWiper (BLUERABBIT) (TL-2026-1147), also tracked as GigaWiper, is a high-severity malware campaign, first published 2026-07-09. It is attributed to IRGC-adjacent cluster (Iran) with medium confidence, affects Microsoft Windows (all supported desktop/server versions), maps to 27 MITRE ATT&CK techniques (T1007, T1016, T1036), and is covered by 9 detection rules and 40 indicators of compromise.
Key facts for TL-2026-1147
- Threat ID
- TL-2026-1147
- Also known as
- GigaWiper, BLUERABBIT
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-07-09
- Last reviewed
- 2026-07-09
- Attribution
- IRGC-adjacent cluster
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Iran
- Motivation
- DESTRUCTION
- Target sectors
- government administration, informationtechnology, criticalinfrastructure, waterandwastewater, energy
- Target regions
- israel, united states of america, united kingdom, ireland
- Detection rules
- 9
- Indicators of compromise
- 40
Malware and tooling in GigaWiper (BLUERABBIT)
Malware and tooling: BLUERABBIT, BLUEWIPE, Crucio, FlockWiper, GigaWiper, SEWERGOO, MinIO S3-compatible storage, MinIO client (mc), RabbitMQ/AMQP, Redis/RESP
GigaWiper, tracked by Microsoft and also identified as BLUERABBIT by Binary Defense (via Google Threat Intelligence Group), is a Go-based Windows backdoor that consolidates a raw-disk wiper, a Crucio-derived fake ransomware (.candy extension), and a Golang reimplementation of the C-based FlockWiper drive overwriter into a single modular tool, alongside espionage features (screenshot/video capture, hidden VNC, keylogger stubs). It abuses legitimate cloud-native services — RabbitMQ (AMQP tasking), Redis (state/results), and MinIO (S3-compatible exfiltration) — for C2, masquerades as OneDrive via a scheduled task and firewall rule, and has targeted Israeli government and IT-sector organizations as part of a suspected Iran-nexus (IRGC-adjacent) destructive campaign whose operators appear to decide destructive intent (wipe vs. fake-ransom vs. espionage-only) post-compromise.
How GigaWiper (BLUERABBIT) works
GigaWiper/BLUERABBIT is a modular, Go-language Windows backdoor first identified by Microsoft (destructive activity dated October 2025) and independently reported by Binary Defense as BLUERABBIT (first observed mid-to-late March 2026), citing Google Threat Intelligence Group (GTIG) report 26-10016354 and linking it to the same Iran-nexus activity cluster that previously deployed BLUEWIPE and SEWERGOO in June 2025.
The malware's defining characteristic is command-driven modularity: a single backdoor exposes numbered commands that let the operator choose the outcome of a compromise after the fact rather than committing to a payload at build time. Command 1 (WipeMain) performs raw physical-disk wiping via WMI enumeration and IOCTL_DISK_CREATE_DISK partition-table destruction followed by sequential randomized-buffer overwrite. Command 2 (BSOD) disables Windows recovery mechanisms via registry modification (CrashControl AutoReboot, WindowsUpdate AU NoAutoRebootWithLoggedOnUsers, Maintenance MaintenanceDisabled), takes ownership of boot-critical files (bootmgr, ntoskrnl.exe, winload) via takeown/icacls, and deletes them to force an unbootable state. Command 3 (RanMain / BigBangExtortMain) is a fake-ransomware routine derived from the Crucio codebase — files are AES-CBC encrypted in chunks with unsaved, randomly generated keys (no decryption is possible even if a ransom were paid), renamed with a .candy extension, and the desktop wallpaper is replaced with an AI-generated extortion image; this function shares code lineage with Crucio ransomware referenced in the December 2023 CISA/NSA/EPA/FBI/INCD joint advisory AA23-335A on IRGC-affiliated ('CyberAv3ngers') actors exploiting Unitronics Vision-series PLCs at US and international water/wastewater facilities. Command 12 (WipeCMain) is a multi-pass secure wipe of the Windows installation drive only, reimplementing the C-based FlockWiper tool (first seen on VirusTotal June 2025) in Go; PDB debug paths in FlockWiper and function names inside GigaWiper both contain a recurring 'GRAT' string suggesting a shared development framework or toolkit lineage across the malware families.
Beyond destructive capability, GigaWiper carries a full espionage/RAT suite: all-monitor screenshot capture, screen recording during active user sessions, hidden VNC for live desktop viewing and remote keyboard/mouse control, shell command execution, system/hardware/network/domain profiling, security-product and BitLocker-status detection, process and service enumeration/management, registry editing, Windows event-log wiping, and dormant keylogger stubs.
Command and control is unusually implemented atop legitimate, widely-deployed backend services rather than bespoke protocols: RabbitMQ over AMQP serves as the primary tasking channel (a device-named queue with the consumer tag set to the malware's own executable path; tasks delivered as JSON via a fanout 'All' exchange for broadcast operations and a 'Topic' exchange for routing-key-targeted deployment to specific victims), Redis (RESP protocol) handles state tracking and result/status reporting, and a MinIO S3-compatible object store is used for staging and exfiltrating large files — data is first written to GUID-named staging directories (a detection opportunity, since the malware's GUID generator uses the full A–Z/0–9 alphanumeric range rather than the hexadecimal-only characters used by legitimate Windows GUIDs) before upload via the MinIO client (mc), frequently invoked with the --insecure flag.
Persistence and masquerade center on impersonating Microsoft OneDrive: on first execution the malware checks/writes HKCU\SOFTWARE\OneDrive\Environment to track execution count, then establishes a scheduled task named 'OneDrive Update' via PowerShell/New-ScheduledTaskAction with a five-second initial delay and 60-second repeat interval, a startup trigger, AllowStartIfOnBatteries, hidden execution, automatic restart (up to three attempts), no execution time limit, and highest available run level. A Windows Firewall rule named 'Microsoft.Windows.CloudExperienceHost' is created to whitelist the malware's outbound traffic under a plausible-sounding built-in Windows component name.
Microsoft Defender detects components of this malware family under the names Giga, Wiper, FlockWiper, and CutBrooch (antivirus signatures) and WprFlock, WprCree, FlockWiper, and GigaWiper (Defender for Endpoint), alongside generic 'Possible ransomware activity' / 'Ransomware behavior detected' alerts. Attribution in both reports points to a suspected Iran-nexus, IRGC-adjacent actor cluster; GTIG links the current wave to the same cluster's June 2025 BLUEWIPE and SEWERGOO deployments, and both Microsoft and Binary Defense connect the Crucio-derived ransomware function to the CyberAv3ngers persona associated with the 2023 Unitronics PLC intrusions against US, Israeli, UK, and Irish water/energy infrastructure. Current targeting (per Binary Defense/Infosecurity Magazine reporting) is concentrated on Israeli government and IT-sector organizations, consistent with the broader escalation of Iran-linked destructive operations against Israel observed through 2025-2026.
MITRE ATT&CK techniques used in TL-2026-1147
Discovery
T1007 System Service Discovery; T1016 System Network Configuration Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1482 Domain Trust Discovery; T1518 Software Discovery
Defense Evasion
T1036 Masquerading; T1070 Indicator Removal
Persistence
T1053 Scheduled Task/Job; T1547 Boot or Logon Autostart Execution
Collection
T1056 Input Capture; T1074 Data Staged; T1113 Screen Capture; T1125 Video Capture
Command and Control
T1071 Application Layer Protocol; T1102 Web Service; T1219 Remote Access Tools
defense-impairment
T1112 Modify Registry; T1222 File and Directory Permissions Modification; T1685 Disable or Modify Tools
Impact
T1485 Data Destruction; T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery; T1491 Defacement; T1529 System Shutdown/Reboot; T1561 Disk Wipe
Exfiltration
Affected products and versions in GigaWiper (BLUERABBIT)
- Microsoft — Windows (all supported desktop/server versions)
Vulnerable versions: Any Windows host reachable by the actor with sufficient privilege to install a scheduled task
Remediation for GigaWiper (BLUERABBIT)
Immediate actions
- Block C2 IPs 185.182.193.21 and 212.8.248.104 at perimeter firewall/proxy
- Hunt for scheduled task named 'OneDrive Update' with 60-second repeat interval and immediate start trigger; do not assume legitimacy from the name alone
- Hunt for Windows Firewall rule named 'Microsoft.Windows.CloudExperienceHost' and validate against known-good baseline rule sets
- Alert on outbound AMQP (RabbitMQ, default 5672/5544) and Redis (RESP, default 6379/7542) connections from endpoint/workstation subnets to non-approved brokers
- Alert on MinIO client (mc) execution with --insecure flag or S3 API calls originating from non-server, non-approved endpoints
- Alert on takeown.exe/icacls.exe execution targeting bootmgr, ntoskrnl.exe, or winload.exe outside change/maintenance windows
- Search for GUID-formatted directory names containing non-hexadecimal characters (G-Z) under Temp/AppData paths
- Isolate and forensically image any host exhibiting HKCU\SOFTWARE\OneDrive\Environment modification combined with OneDrive Update scheduled task creation
- Immediately snapshot/backup critical systems offline; verify backups are isolated from the RabbitMQ/Redis/MinIO C2 path
Workarounds
- Restrict outbound connectivity to public RabbitMQ/Redis/MinIO SaaS or self-hosted endpoints via egress proxy allowlisting
- Disable or tightly scope PowerShell New-ScheduledTaskAction usage for non-administrative users via AppLocker/WDAC
Longer-term hardening
- Deploy EDR with behavioral detection for disk-level IOCTL calls (IOCTL_DISK_CREATE_DISK) and mass file rename/encryption patterns
- Implement application allowlisting to block unauthorized mc.exe / MinIO client binaries on endpoints
- Network-segment and monitor egress for AMQP/RabbitMQ and Redis protocols; these are rarely legitimate from end-user workstations
- Harden Windows recovery: monitor and alert on changes to CrashControl, WindowsUpdate\AU, and Schedule\Maintenance registry keys
- Maintain offline, immutable backups with tested restoration procedures given the destructive/irreversible nature of the wiper modules
- Track GTIG/Binary Defense/Microsoft threat intel updates on BLUEWIPE, SEWERGOO, and GigaWiper/BLUERABBIT for expanded IOC sets
- Deploy JA3/JA3S/JA4 TLS fingerprint detection at the network layer for the published fingerprints associated with this cluster's C2
Timeline of GigaWiper (BLUERABBIT)
- IRGC-affiliated 'CyberAv3ngers' actors begin compromising internet-accessible Unitronics Vision-series PLCs/HMIs at US and international water/wastewater facilities, compromising at least 75 devices (34+ in US WWS sector); this activity is the earliest documented use of the code lineage later found in Crucio/GigaWiper's ransomware module.
- CISA, NSA, EPA, FBI, and Israel's INCD jointly publish advisory AA23-335A on IRGC-affiliated cyber actors exploiting PLCs across multiple critical infrastructure sectors, later cited by Microsoft and Binary Defense as the origin of the Crucio ransomware code shared with GigaWiper's RanMain/BigBangExtortMain function.
- Tenable publishes a FAQ on the CyberAv3ngers/IRGC-linked threat group, establishing the public attribution background that Microsoft and Binary Defense later cite when tying GigaWiper's Crucio-derived ransomware module to the same actor lineage.
- Google Threat Intelligence Group observes the same suspected Iran-nexus activity cluster deploying BLUEWIPE and SEWERGOO malware, later assessed as related to the GigaWiper/BLUERABBIT campaign.
- The original C-language FlockWiper drive-overwriting tool is first observed on VirusTotal, later reimplemented in Go as GigaWiper's WipeCMain (Command 12).
- Microsoft dates the earliest observed destructive GigaWiper activity to October 2025.
- Secondary security-news outlets (cybersecuritynews.com, gbhackers.com, cyberpress.org) republish and expand on Binary Defense's BLUERABBIT findings, and Infosecurity Magazine separately reports the cluster's targeting of Israeli government and IT-sector organizations.
- Binary Defense first observes the malware, tracked as BLUERABBIT, in the wild targeting entities in Israel, citing Google Threat Intelligence Group report 26-10016354.
- Microsoft publishes a detailed technical blog on GigaWiper including IOCs and Defender detection names; The Hacker News publicizes the campaign, describing targeting of Israeli government and IT-sector organizations.
- Microsoft ships Defender antivirus signatures (Giga, Wiper, FlockWiper, CutBrooch) and Defender for Endpoint alert names (WprFlock, WprCree, FlockWiper, GigaWiper) alongside generic ransomware-behavior alerts covering the malware family's components.
Sources cited for GigaWiper (BLUERABBIT)
- New GigaWiper Windows Backdoor Bundles Destructive Wiper, Fake Ransomware, and Espionage Tools
- GigaWiper: Anatomy of a Destructive Backdoor Assembled from Multiple Malware
- BLUERABBIT: A Golang-Based Backdoor with Ransomware and Destructive Capabilities
- Hackers Use BLUERABBIT Backdoor to Encrypt Files and Wipe Disks Across Windows Systems
- BLUERABBIT Backdoor Encrypts Files, Wipes Windows Systems
- BLUERABBIT Backdoor Targets Windows Systems With File Encryption
- New Iran-Nexus Hacking Group Targets Israel Government and IT Sectors
- IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors, Including US Water and Wastewater Systems Facilities (AA23-335A)
- Iran-Linked CyberAv3ngers Sets Sights on Water Utilities and Industrial Controllers
- CyberAv3ngers: FAQ About Iran-Linked Threat Group Targeting U.S. Critical Infrastructure
Threats related to GigaWiper (BLUERABBIT)
- GigaWiper (aka BLUERABBIT): Golang-Based Destructive Backdoor Combining Wiper, Fake Ransomware, and C2 Capabilities
- GigaWiper: Multi-Stage Destructive Windows Backdoor Combining Disk Wiping, File Encryption, and Boot Sabotage (CyberAv3ngers/Crucio/FlockWiper Lineage)
- GigaWiper (BLUERABBIT): Golang Backdoor Bundling Physical-Disk Wiping, Crucio-Derived Fake Ransomware, and FlockWiper-Derived Multi-Pass Wiping
- Sage Water Resources Utah saltwater disposal facility PLC intrusion — Iranian IRGC-CEC (CyberAv3ngers) logic manipulation bypasses pump safeguards
- Iranian-Aligned Cyber Mobilization — 60+ Groups Targeting US Critical Infrastructure ICS/SCADA with AI-Assisted Reconnaissance Post Iran-US Escalation (Feb 28, 2026)
Detection coverage for TL-2026-1147
As of 2026-07-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1147 across Splunk SPL, Microsoft KQL and Sigma, covering 40 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-1147
2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.