GigaWiper malware wipes storage drives and spies on your desktop simultaneously
Microsoft has published an analysis of GigaWiper, a new multi-function malware that can permanently wipe storage drives by overwriting raw disk content and removing partition metadata, making recovery impossible. It also includes desktop spyware capabilities. The malware appears to be a hybrid of several malware families and uses multiple methods to irreversibly destroy data, including repeated overwrites with different byte patterns.
Full text
I run a single SSD gaming PC, which I'm aware is giving me a wonderful case of 'single-point-of-failure-itus.' Which is why my ears (eyes?) perked up when I read about GigaWiper, a wonderfully-named malware that can potentially do terrible things to your storage drives.
Microsoft has published an analysis into GigaWiper's capabilities, and it looks to be a multi-faceted, tricksy piece of malware with a pretty unique USP (via MalwareBytes ). It appears to be the result of several malware families stitched together, and is capable of wiping your drives at the physical disk level, "overwriting raw disk content and removing partition metadata."
The nasty little beastie has several ways to irreversibly destroy your data. There's a Windows drive secure wiper for starters, which targets an installation and performs multiple overwrites using different byte patterns, making the original data virtually impossible to retrieve.
Another method identifies physical disk drives, confirms which drive contains a Windows installation, removes the partition references from your other drives, overwrites the raw disk content with randomized data, and reboots your system for good measure.
Keep your fork, there's more. Another Crucio-based wiper imitates traditional ransomware, but instead of demanding payment, encrypts your files and then "throws away the encryption key" instead, according to MalwareBytes.
(Image credit: Pixabay (Elchinator)) GigaWiper's all-in-one approach also means it's capable of capturing your screen, streaming your desktop, and allowing remote control of your machine via an outside TCP server, all while hiding itself under the cover of a scheduled OneDrive task. Jolly good.
The good news for us home PC users is that GigaWiper seems to be targeted towards organisations rather than individual machines, and can only operate after breaching a PC in the first place—so the usual "keep your security software updated" advice should be enough for the majority.
For sysadmins, though, Microsoft recommends multiple network-hardening methods (including "tenant-wide tamper protection") to stop breaches before they occur. This is one piece of Malware you really don't want running rampant through your IT infrastructure, so I'd take this as yet another reason to have a thorough review of your security practices.
💻 Technology
Microsoft warns of Iranian GigaWiper malware that wipes drives and fakes ransomware
TechRadar · 13d ago
💻 Technology
ChatGPT enters top-10 most-impersonated brands — Microsoft and LinkedIn still lead
TechRadar · 1h ago
💻 Technology
Trojan NuGet package rigged live betting game outcomes at a specific platform
TechRadar · 18h ago
💻 Technology
Microsoft Makes Passkeys Default for Entra ID from September 2026, Drops SMS Auth in 2027
TechRadar · 19h ago
💻 Technology
Dolphin X malware uses AI to rank victims and alert hackers daily
TechRadar · 22h ago
💻 Technology
Developer Discovers Take-Home Interview Project Was Malware Hidden in a Git Hook
Hacker News · 1d ago
💻 Technology
Microsoft warns of Iranian GigaWiper malware that wipes drives and fakes ransomware
TechRadar · 13d ago
💻 Technology
ChatGPT enters top-10 most-impersonated brands — Microsoft and LinkedIn still lead
TechRadar · 1h ago
💻 Technology
Trojan NuGet package rigged live betting game outcomes at a specific platform
TechRadar · 18h ago
Should companies be legally required to notify users about threats like GigaWiper?
Comments
No comments yet
Comments
No comments yet — be the first to weigh in 👇
No comments yet. Be the first!