HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

GigaWiper Malware Enables Remote Control and Full Disk Wipe on Windows Systems

Microsoft reports GigaWiper, a modular Golang backdoor that provides persistent remote access and multiple disk‑wiping commands. The threat underscores the need for SOC 2‑aligned access controls and continuous monitoring to meet audit readiness.

LiveThreat™ Intelligence · 📅 July 11, 2026· 📰 malwarebytes.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
malwarebytes.com

GigaWiper Malware Enables Remote Control and Full Disk Wipe on Windows Systems

What Happened — Microsoft disclosed a new modular Golang backdoor, GigaWiper, that has been observed in the wild since October 2025. The malware provides persistent remote access, system‑inventory capabilities, and multiple destructive commands that can overwrite raw disks or encrypt files and discard the keys, effectively wiping a machine clean.

Why It Matters for Compliance & Audit Readiness

  • Demonstrates the need for SOC 2‑aligned Access Controls that restrict privileged local admin rights and enforce least‑privilege on workstations.
  • Highlights the importance of continuous monitoring and immutable logging to provide audit‑ready evidence of suspicious activity before a destructive payload is triggered.
  • Shows that incident‑response playbooks must include rapid network isolation and tamper‑protection verification to meet the SOC 2 CC6.1 “System Operations” requirement.

Who Is Affected — Any organization that relies on Windows endpoints, spanning finance, healthcare, SaaS, and government sectors.

Recommended Actions

  • Review and tighten endpoint admin privileges; enforce MFA for local admin accounts.
  • Deploy tamper‑protected endpoint protection that logs and alerts on creation of scheduled tasks or firewall rule changes.
  • Integrate real‑time EDR telemetry into a SOC 2‑compatible evidence repository for continuous control monitoring.

Source: Malwarebytes Labs

Technical Notes

  • GigaWiper is a Golang‑based backdoor with ~20 C2 commands covering destruction, remote control, and system management.
  • Persistence via a scheduled task (“OneDrive Update”) and firewall rule injection.
  • C2 servers observed at 185.182.193[.]21 and 212.8.248[.]104.
📰 Original Source
https://www.malwarebytes.com/blog/news/2026/07/this-new-windows-malware-can-take-over-your-pc-and-wipe-it-clean

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your SOC 2 posture defensible.

See where you'd stand with Verisq AI Trust Operations →