type: entity ยท created: 2026-07-11 ยท updated: 2026-07-11 ยท tags: [wiper, rat, cybercrime-group] ยท confidence: medium ยท affected_sectors: [technology] ยท au_impact: false
GigaWiper / BLUERABBIT
GigaWiper (also tracked as BLUERABBIT) is a destructive Windows backdoor analyzed by Microsoft that combines three older destructive programs into a single modular malware platform. It is tentatively linked to likely Iranian state-aligned actors via Google's GTIG analysis.
Capabilities
- Disk wiping: Destructive capability that overwrites data
- Fake ransomware: Mimics ransomware behaviour without genuine recovery mechanisms
- Spyware: Information theft and surveillance functions
- Backdoor: Persistent remote access to compromised systems
Defense
- No patch available โ detection and offline backups are the primary defences
- MITRE ATT&CK detections recommended by Microsoft
Attribution
Analysis by Google GTIG suggests links to Iran-linked actors, though attribution is not confirmed at high confidence. (raw/digests/Cyber-Digest-2026-07-10)
Related Pages
- Goddamn Ransomware โ Different destructive malware using kernel driver evasion
- Ghostlock โ Critical vulnerability enabling privilege escalation