GigaWiper (aka BLUERABBIT): Golang-Based Destructive Backdoor Combining Wiper, Fake Ransomware, and C2 Capabilities

GigaWiper (aka BLUERABBIT) (TL-2026-1158), also tracked as BLUERABBIT, is a critical-severity malware campaign, first published 2026-07-10. It is attributed to Cyber Av3ngers (Iran) with medium confidence, affects Microsoft Windows (all supported client/server versions), maps to 24 MITRE ATT&CK techniques (T1021, T1036, T1053), and is covered by 9 detection rules and 28 indicators of compromise.

Key facts for TL-2026-1158

Threat ID
TL-2026-1158
Also known as
BLUERABBIT, GigaWiper
Severity
CRITICAL
Status
ACTIVE
Category
MALWARE
First published
2026-07-10
Last reviewed
2026-07-10
Attribution
Cyber Av3ngers
Attribution confidence
MEDIUM
Nation-state nexus
Iran
Motivation
DESTRUCTION
Target sectors
government administration, energy, waterandwastewater, criticalinfrastructure
Target regions
israel, united states of america, united kingdom, ireland
Detection rules
9
Indicators of compromise
28

Malware and tooling in GigaWiper (aka BLUERABBIT)

Malware and tooling: BLUERABBIT, Crucio, FlockWiper, GigaWiper, MinIO, RabbitMQ, Redis

Microsoft identified GigaWiper, a Golang-based backdoor that unifies command-and-control with multiple destructive payloads — physical disk wiping, non-recoverable AES-256-CBC file encryption (fake ransomware), and boot/recovery sabotage triggering BSOD. Microsoft assesses the same developer built GigaWiper, Crucio ransomware, and FlockWiper, consolidating three previously distinct malware families into one modular framework.

How GigaWiper (aka BLUERABBIT) works

GigaWiper is a Golang-compiled backdoor first observed conducting destructive activity in October 2025 and publicly documented by Microsoft Threat Intelligence on 2026-07-09 (independently tracked as BLUERABBIT by Binary Defense since March 2026). The malware receives tasking over RabbitMQ (AMQP, port 5544) using a fanout exchange named "All" for broadcast commands and a topic exchange for targeted tasking, reports status/output via Redis (port 7542), and can exfiltrate files to attacker-controlled MinIO object storage — all legitimate open-source message-broker/storage technologies repurposed as camouflaged C2 transport. Hard-coded C2 credentials and configuration are protected with AES decryption.

The backdoor exposes 20 numbered command codes to the operator, ranging from routine RAT functionality (PowerShell execution with directory persistence, process/service/registry management, system and security-software enumeration, idle-aware screenshot/screen-recording capture, VNC-like remote desktop control via Command 20, Windows event log clearing across System/Setup/Application/Security/ForwardedEvents channels, and firewall rule manipulation) to three distinct destructive payloads that were previously separate malware families: Command 1 (WipeMain) performs physical-disk-level wiping via DeviceIoControl with IOCTL_DISK_CREATE_DISK, overwriting raw disk content in 0xA00000-byte chunks; Command 2 disables Windows Recovery and deletes critical boot/kernel files to force a BSOD/unbootable state; Command 3 (BigBangExtortMain) is fake ransomware — AES-256-CBC encryption with randomly generated, never-persisted keys/IVs, appending a `.candy` extension and dropping a hard-coded wallpaper (`./image_danger.jpg`) — code Microsoft found 'heavily based on' Crucio ransomware, sharing the identical BigBangExtortMain function name; and Command 12 (WipeCMain) is a Golang re-implementation of FlockWiper, a standalone C-language multi-pass wiper first uploaded to VirusTotal in June 2025, targeting only the Windows installation drive with multiple secure overwrite passes.

Microsoft ties all three malware families (GigaWiper, Crucio, FlockWiper) to a single developer based on PDB-path and function-naming overlap referencing the string "GRAT" in both FlockWiper and GigaWiper, suggesting the possible existence of a related, still-undocumented "GRAT" framework component. Crucio ransomware was previously documented by CISA in December 2023 in connection with IRGC-affiliated cyber actors (the CyberAv3ngers persona) that exploited internet-exposed Unitronics Vision-series PLCs at U.S. water/wastewater facilities; subsequent open-source reporting (Binary Defense / Google Threat Intelligence Group) assesses the same Iran-nexus actor conducted destructive GigaWiper/BLUERABBIT operations primarily against Israeli organizations, consistent with the CyberAv3ngers group's broader pattern of destructive operations against US, Israeli, UK, and Irish water and energy-sector targets from 2023-2026. Persistence is achieved via a scheduled task named "OneDrive Update" that runs at system startup and every minute thereafter, invoking PowerShell with hidden-window execution parameters and tracked via a benign-looking registry key (HKCU\SOFTWARE\OneDrive\Environment). Defense evasion includes masquerading a firewall rule as the legitimate Windows component "Microsoft.Windows.CloudExperienceHost" and direct deletion of Windows Security event log files. Dormant/unused code paths include keylogger stubs and additional wiper-module scaffolding not yet activated in observed samples, indicating the framework is under active development.

MITRE ATT&CK techniques used in TL-2026-1158

Lateral Movement

T1021 Remote Services

Defense Evasion

T1036 Masquerading; T1070 Indicator Removal; T1140 Deobfuscate/Decode Files or Information

Persistence

T1053 Scheduled Task/Job; T1547 Boot or Logon Autostart Execution

Collection

T1056 Input Capture; T1113 Screen Capture

Discovery

T1057 Process Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1518 Software Discovery

Execution

T1059 Command and Scripting Interpreter

Command and Control

T1071 Application Layer Protocol; T1571 Non-Standard Port; T1573 Encrypted Channel

defense-impairment

T1112 Modify Registry; T1685 Disable or Modify Tools

Impact

T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery; T1491 Defacement; T1529 System Shutdown/Reboot; T1561 Disk Wipe

Exfiltration

T1567 Exfiltration Over Web Service

Affected products and versions in GigaWiper (aka BLUERABBIT)

  • Microsoft — Windows (all supported client/server versions)
    Vulnerable versions: all supported Windows versions targeted by the backdoor

Remediation for GigaWiper (aka BLUERABBIT)

Immediate actions

  • Block C2 IPs 185.182.193.21 and 212.8.248.104 at perimeter firewall/proxy
  • Enable and enforce Microsoft Defender tamper protection to prevent AV/EDR disablement
  • Hunt for scheduled task 'OneDrive Update' and registry key HKCU\SOFTWARE\OneDrive\Environment
  • Hunt for firewall rules masquerading as 'Microsoft.Windows.CloudExperienceHost'
  • Alert on unexpected RabbitMQ (5544) / Redis (7542) outbound connections from endpoints
  • Alert on mass file renames to '.candy' extension and creation of image_danger.jpg wallpaper drops
  • Alert on DeviceIoControl calls with IOCTL_DISK_CREATE_DISK from unsigned/unknown processes

Workarounds

  • Disable or tightly restrict PowerShell execution policy on endpoints where not operationally required
  • Require multi-factor authentication and monitor for anomalous scheduled-task creation

Longer-term hardening

  • Deploy EDR with behavioral detection tuned to disk-wipe and mass-encryption indicators
  • Enforce offline/immutable backups given non-recoverable encryption design
  • Segment and monitor water/energy/critical-infrastructure OT-adjacent IT networks
  • Restrict outbound access for message-broker protocols (AMQP/Redis) not used by business applications
  • Deploy Windows Event Log forwarding to a hardened SIEM to defeat local log-clearing

Timeline of GigaWiper (aka BLUERABBIT)

  • CISA, FBI, NSA, EPA, and INCD publish joint advisory AA23-335A on IRGC-affiliated CyberAv3ngers actors exploiting internet-exposed Unitronics PLCs at US water/wastewater facilities; Crucio ransomware later linked to this actor cluster.
  • FlockWiper, the standalone C-language multi-pass wiper later re-implemented in Go as GigaWiper Command 12, is first uploaded to VirusTotal.
  • Microsoft Threat Intelligence identifies destructive wiping activity in the wild and attributes it to the previously undocumented GigaWiper backdoor.
  • Binary Defense independently observes and begins tracking the same malware family under the name BLUERABBIT.
  • The Hacker News and HackRead publish independent coverage of the Microsoft report, adding the BLUERABBIT alias and Israel-focused victimology assessment.
  • Microsoft ties GigaWiper and FlockWiper to a single developer via shared PDB path artifacts referencing the string 'GRAT' (e.g. A:\GRAT\CWipeNew\Release\CWipeNew.pdb and E:\files\new\GRAT\CWipe\Release\CWipe.pdb found in FlockWiper), and separately ties GigaWiper's Command 3 to Crucio via the identical BigBangExtortMain function name, suggesting an undocumented 'GRAT' framework component.
  • Microsoft Security Blog publishes 'GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware,' detailing the backdoor's C2, wiper, and fake-ransomware modules and linking it to Crucio and FlockWiper.
  • Threat ingested and researched into the Threadlinqs Intelligence Platform (TL-2026-1158).

Sources cited for GigaWiper (aka BLUERABBIT)

Threats related to GigaWiper (aka BLUERABBIT)

Detection coverage for TL-2026-1158

As of 2026-07-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1158 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Community OSINT corroboration for TL-2026-1158

2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats