GigaWiper (aka BLUERABBIT): Golang-Based Destructive Backdoor Combining Wiper, Fake Ransomware, and C2 Capabilities
GigaWiper (aka BLUERABBIT) (TL-2026-1158), also tracked as BLUERABBIT, is a critical-severity malware campaign, first published 2026-07-10. It is attributed to Cyber Av3ngers (Iran) with medium confidence, affects Microsoft Windows (all supported client/server versions), maps to 24 MITRE ATT&CK techniques (T1021, T1036, T1053), and is covered by 9 detection rules and 28 indicators of compromise.
Key facts for TL-2026-1158
- Threat ID
- TL-2026-1158
- Also known as
- BLUERABBIT, GigaWiper
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-07-10
- Last reviewed
- 2026-07-10
- Attribution
- Cyber Av3ngers
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Iran
- Motivation
- DESTRUCTION
- Target sectors
- government administration, energy, waterandwastewater, criticalinfrastructure
- Target regions
- israel, united states of america, united kingdom, ireland
- Detection rules
- 9
- Indicators of compromise
- 28
Malware and tooling in GigaWiper (aka BLUERABBIT)
Malware and tooling: BLUERABBIT, Crucio, FlockWiper, GigaWiper, MinIO, RabbitMQ, Redis
Microsoft identified GigaWiper, a Golang-based backdoor that unifies command-and-control with multiple destructive payloads — physical disk wiping, non-recoverable AES-256-CBC file encryption (fake ransomware), and boot/recovery sabotage triggering BSOD. Microsoft assesses the same developer built GigaWiper, Crucio ransomware, and FlockWiper, consolidating three previously distinct malware families into one modular framework.
How GigaWiper (aka BLUERABBIT) works
GigaWiper is a Golang-compiled backdoor first observed conducting destructive activity in October 2025 and publicly documented by Microsoft Threat Intelligence on 2026-07-09 (independently tracked as BLUERABBIT by Binary Defense since March 2026). The malware receives tasking over RabbitMQ (AMQP, port 5544) using a fanout exchange named "All" for broadcast commands and a topic exchange for targeted tasking, reports status/output via Redis (port 7542), and can exfiltrate files to attacker-controlled MinIO object storage — all legitimate open-source message-broker/storage technologies repurposed as camouflaged C2 transport. Hard-coded C2 credentials and configuration are protected with AES decryption.
The backdoor exposes 20 numbered command codes to the operator, ranging from routine RAT functionality (PowerShell execution with directory persistence, process/service/registry management, system and security-software enumeration, idle-aware screenshot/screen-recording capture, VNC-like remote desktop control via Command 20, Windows event log clearing across System/Setup/Application/Security/ForwardedEvents channels, and firewall rule manipulation) to three distinct destructive payloads that were previously separate malware families: Command 1 (WipeMain) performs physical-disk-level wiping via DeviceIoControl with IOCTL_DISK_CREATE_DISK, overwriting raw disk content in 0xA00000-byte chunks; Command 2 disables Windows Recovery and deletes critical boot/kernel files to force a BSOD/unbootable state; Command 3 (BigBangExtortMain) is fake ransomware — AES-256-CBC encryption with randomly generated, never-persisted keys/IVs, appending a `.candy` extension and dropping a hard-coded wallpaper (`./image_danger.jpg`) — code Microsoft found 'heavily based on' Crucio ransomware, sharing the identical BigBangExtortMain function name; and Command 12 (WipeCMain) is a Golang re-implementation of FlockWiper, a standalone C-language multi-pass wiper first uploaded to VirusTotal in June 2025, targeting only the Windows installation drive with multiple secure overwrite passes.
Microsoft ties all three malware families (GigaWiper, Crucio, FlockWiper) to a single developer based on PDB-path and function-naming overlap referencing the string "GRAT" in both FlockWiper and GigaWiper, suggesting the possible existence of a related, still-undocumented "GRAT" framework component. Crucio ransomware was previously documented by CISA in December 2023 in connection with IRGC-affiliated cyber actors (the CyberAv3ngers persona) that exploited internet-exposed Unitronics Vision-series PLCs at U.S. water/wastewater facilities; subsequent open-source reporting (Binary Defense / Google Threat Intelligence Group) assesses the same Iran-nexus actor conducted destructive GigaWiper/BLUERABBIT operations primarily against Israeli organizations, consistent with the CyberAv3ngers group's broader pattern of destructive operations against US, Israeli, UK, and Irish water and energy-sector targets from 2023-2026. Persistence is achieved via a scheduled task named "OneDrive Update" that runs at system startup and every minute thereafter, invoking PowerShell with hidden-window execution parameters and tracked via a benign-looking registry key (HKCU\SOFTWARE\OneDrive\Environment). Defense evasion includes masquerading a firewall rule as the legitimate Windows component "Microsoft.Windows.CloudExperienceHost" and direct deletion of Windows Security event log files. Dormant/unused code paths include keylogger stubs and additional wiper-module scaffolding not yet activated in observed samples, indicating the framework is under active development.
MITRE ATT&CK techniques used in TL-2026-1158
Lateral Movement
Defense Evasion
T1036 Masquerading; T1070 Indicator Removal; T1140 Deobfuscate/Decode Files or Information
Persistence
T1053 Scheduled Task/Job; T1547 Boot or Logon Autostart Execution
Collection
T1056 Input Capture; T1113 Screen Capture
Discovery
T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1518 Software Discovery
Execution
T1059 Command and Scripting Interpreter
Command and Control
T1071 Application Layer Protocol; T1571 Non-Standard Port; T1573 Encrypted Channel
defense-impairment
T1112 Modify Registry; T1685 Disable or Modify Tools
Impact
T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery; T1491 Defacement; T1529 System Shutdown/Reboot; T1561 Disk Wipe
Exfiltration
Affected products and versions in GigaWiper (aka BLUERABBIT)
- Microsoft — Windows (all supported client/server versions)
Vulnerable versions: all supported Windows versions targeted by the backdoor
Remediation for GigaWiper (aka BLUERABBIT)
Immediate actions
- Block C2 IPs 185.182.193.21 and 212.8.248.104 at perimeter firewall/proxy
- Enable and enforce Microsoft Defender tamper protection to prevent AV/EDR disablement
- Hunt for scheduled task 'OneDrive Update' and registry key HKCU\SOFTWARE\OneDrive\Environment
- Hunt for firewall rules masquerading as 'Microsoft.Windows.CloudExperienceHost'
- Alert on unexpected RabbitMQ (5544) / Redis (7542) outbound connections from endpoints
- Alert on mass file renames to '.candy' extension and creation of image_danger.jpg wallpaper drops
- Alert on DeviceIoControl calls with IOCTL_DISK_CREATE_DISK from unsigned/unknown processes
Workarounds
- Disable or tightly restrict PowerShell execution policy on endpoints where not operationally required
- Require multi-factor authentication and monitor for anomalous scheduled-task creation
Longer-term hardening
- Deploy EDR with behavioral detection tuned to disk-wipe and mass-encryption indicators
- Enforce offline/immutable backups given non-recoverable encryption design
- Segment and monitor water/energy/critical-infrastructure OT-adjacent IT networks
- Restrict outbound access for message-broker protocols (AMQP/Redis) not used by business applications
- Deploy Windows Event Log forwarding to a hardened SIEM to defeat local log-clearing
Timeline of GigaWiper (aka BLUERABBIT)
- CISA, FBI, NSA, EPA, and INCD publish joint advisory AA23-335A on IRGC-affiliated CyberAv3ngers actors exploiting internet-exposed Unitronics PLCs at US water/wastewater facilities; Crucio ransomware later linked to this actor cluster.
- FlockWiper, the standalone C-language multi-pass wiper later re-implemented in Go as GigaWiper Command 12, is first uploaded to VirusTotal.
- Microsoft Threat Intelligence identifies destructive wiping activity in the wild and attributes it to the previously undocumented GigaWiper backdoor.
- Binary Defense independently observes and begins tracking the same malware family under the name BLUERABBIT.
- The Hacker News and HackRead publish independent coverage of the Microsoft report, adding the BLUERABBIT alias and Israel-focused victimology assessment.
- Microsoft ties GigaWiper and FlockWiper to a single developer via shared PDB path artifacts referencing the string 'GRAT' (e.g. A:\GRAT\CWipeNew\Release\CWipeNew.pdb and E:\files\new\GRAT\CWipe\Release\CWipe.pdb found in FlockWiper), and separately ties GigaWiper's Command 3 to Crucio via the identical BigBangExtortMain function name, suggesting an undocumented 'GRAT' framework component.
- Microsoft Security Blog publishes 'GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware,' detailing the backdoor's C2, wiper, and fake-ransomware modules and linking it to Crucio and FlockWiper.
- Threat ingested and researched into the Threadlinqs Intelligence Platform (TL-2026-1158).
Sources cited for GigaWiper (aka BLUERABBIT)
- GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware
- New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware
- Microsoft Warns of GigaWiper Backdoor Built to Destroy Windows PCs
- IRGC-Affiliated Cyber Actors Exploit PLCs in Multiple Sectors, Including US Water and Wastewater Systems Facilities
- CISA and Partners Release Joint Advisory on IRGC-Affiliated Cyber Actors Exploiting PLCs
- IRGC-Affiliated Cyber Actors Exploit Programmable Logic Controllers (Joint Advisory PDF)
Threats related to GigaWiper (aka BLUERABBIT)
- GigaWiper (BLUERABBIT) — Go-Based Modular Backdoor Bundles Raw Disk Wiper, Crucio-Derived Fake Ransomware, and FlockWiper Drive Overwriter Behind Espionage Tooling
- GigaWiper: Multi-Stage Destructive Windows Backdoor Combining Disk Wiping, File Encryption, and Boot Sabotage (CyberAv3ngers/Crucio/FlockWiper Lineage)
- GigaWiper (BLUERABBIT): Golang Backdoor Bundling Physical-Disk Wiping, Crucio-Derived Fake Ransomware, and FlockWiper-Derived Multi-Pass Wiping
- Sage Water Resources Utah saltwater disposal facility PLC intrusion — Iranian IRGC-CEC (CyberAv3ngers) logic manipulation bypasses pump safeguards
- Iranian-Aligned Cyber Mobilization — 60+ Groups Targeting US Critical Infrastructure ICS/SCADA with AI-Assisted Reconnaissance Post Iran-US Escalation (Feb 28, 2026)
Detection coverage for TL-2026-1158
As of 2026-07-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1158 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-1158
2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.