HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

GigaWiper Malware Merges Three Families into a Single Destructive Go Backdoor

Microsoft uncovered GigaWiper, a modular Go backdoor that combines espionage, remote‑control, and disk‑wiping capabilities by merging code from three older malware families. The threat illustrates the need for continuous endpoint‑security controls and audit‑ready evidence in SOC 2 programs.

LiveThreat™ Intelligence · 📅 July 10, 2026· 📰 securityaffairs.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
2 recommended
📰
Source
securityaffairs.com

GigaWiper Malware Unites Three Families into a Single Destructive Go Backdoor

What Happened — Microsoft identified a new modular backdoor, dubbed GigaWiper, that fuses code from three prior malware families. The implant, written in Go, provides espionage, remote‑control, and multiple disk‑wiping capabilities, persisting via a scheduled task masquerading as a OneDrive update.

Why It Matters for Compliance & Audit Readiness

  • Demonstrates how a single implant can bypass fragmented endpoint controls, underscoring the need for continuous, mapped security controls that can be evidenced during a SOC 2 audit.
  • Highlights the importance of maintaining up‑to‑date detection coverage and audit‑ready logs for scheduled tasks and registry artifacts.
  • Aligns with Verisq’s Control Mapping capability, which automates evidence collection for endpoint‑security controls to satisfy SOC 2 Trust Services Criteria.

Who Is Affected — Primarily technology and SaaS providers, cloud‑infrastructure operators, and any organization with Windows endpoints.

Recommended Actions — Map endpoint‑security controls (e.g., scheduled‑task monitoring, registry change detection) to SOC 2 criteria, implement continuous log collection, and validate that evidence is retained for audit review. Source: Security Affairs

Technical Notes — The backdoor uses RabbitMQ for C2, Redis for result exfiltration, and persists via a “OneDrive Update” scheduled task. Destructive commands include raw‑disk wiping, forced BSOD, and unrecoverable encryption with a .candy extension. Source: Security Affairs

📰 Original Source
https://securityaffairs.com/195068/malware/gigawiper-merges-three-malware-families-into-one-destructive-backdoor.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →