Microsoft warns of a new modular malware package dubbed “GigaWiper” that is designed to support both espionage and destructive actions on compromised Windows systems. Multiple outlets describe the tool as a multi-malware combination that draws on techniques and code associated with several different malware families, assembled into a single deployment package for threat actors.
According to the reporting, GigaWiper can perform wiper activity aimed at damaging or wiping systems. Sources also describe ransomware-related encryption capabilities, and at least one account references a multi-pass wiping command that can repeatedly target system data. In addition to destruction, the malware is described as supporting “quiet” operations, including the ability to spy on users or conduct backdoor-style activity while remaining less overt.
Across the coverage, the main common thread is that the same implant can deliver multiple outcomes—data destruction and impact maximization—while reducing the need for separate tools. The reports attribute the analysis and naming to Microsoft and emphasize that the modular design can be selected and used by threat actors to fit their operational goals.