GigaWiper Malware Enables Remote Control and Full Disk Wipe on Windows Systems
What Happened — Microsoft disclosed a new modular Golang backdoor, GigaWiper, that has been observed in the wild since October 2025. The malware provides persistent remote access, system‑inventory capabilities, and multiple destructive commands that can overwrite raw disks or encrypt files and discard the keys, effectively wiping a machine clean.
Why It Matters for Compliance & Audit Readiness
- Demonstrates the need for SOC 2‑aligned Access Controls that restrict privileged local admin rights and enforce least‑privilege on workstations.
- Highlights the importance of continuous monitoring and immutable logging to provide audit‑ready evidence of suspicious activity before a destructive payload is triggered.
- Shows that incident‑response playbooks must include rapid network isolation and tamper‑protection verification to meet the SOC 2 CC6.1 “System Operations” requirement.
Who Is Affected — Any organization that relies on Windows endpoints, spanning finance, healthcare, SaaS, and government sectors.
Recommended Actions
- Review and tighten endpoint admin privileges; enforce MFA for local admin accounts.
- Deploy tamper‑protected endpoint protection that logs and alerts on creation of scheduled tasks or firewall rule changes.
- Integrate real‑time EDR telemetry into a SOC 2‑compatible evidence repository for continuous control monitoring.
Source: Malwarebytes Labs
Technical Notes
- GigaWiper is a Golang‑based backdoor with ~20 C2 commands covering destruction, remote control, and system management.
- Persistence via a scheduled task (“OneDrive Update”) and firewall rule injection.
- C2 servers observed at 185.182.193[.]21 and 212.8.248[.]104.