Home ยท Wiki ยท Entities & Threat Actors
type: entity ยท created: 2026-07-11 ยท updated: 2026-07-11 ยท tags: [wiper, rat, cybercrime-group] ยท confidence: medium ยท affected_sectors: [technology] ยท au_impact: false

GigaWiper / BLUERABBIT

GigaWiper (also tracked as BLUERABBIT) is a destructive Windows backdoor analyzed by Microsoft that combines three older destructive programs into a single modular malware platform. It is tentatively linked to likely Iranian state-aligned actors via Google's GTIG analysis.

Capabilities

  • Disk wiping: Destructive capability that overwrites data
  • Fake ransomware: Mimics ransomware behaviour without genuine recovery mechanisms
  • Spyware: Information theft and surveillance functions
  • Backdoor: Persistent remote access to compromised systems

Defense

  • No patch available โ€” detection and offline backups are the primary defences
  • MITRE ATT&CK detections recommended by Microsoft

Attribution

Analysis by Google GTIG suggests links to Iran-linked actors, though attribution is not confirmed at high confidence. (raw/digests/Cyber-Digest-2026-07-10)

Related Pages

  • Goddamn Ransomware โ€” Different destructive malware using kernel driver evasion
  • Ghostlock โ€” Critical vulnerability enabling privilege escalation