A modular implant borrows from various malware families to combine both backdoor and wiper activities to maximize impact and minimize operational output.
July 13, 2026
A novel modular malware lets attackers choose their own adventure regarding how they want to destroy a targeted system.
The malware, described as "a wiper inside a backdoor," combines multiple malware capabilities into a single implant that allows attackers to maximize their impact while minimizing their operational footprint. Researchers initially spotted the malware, dubbed GigaWiper, during "destructive wiper activity" in October 2025 and thought they were looking at a Golang-based backdoor, according to a recent post on the Microsoft Threat Intelligence (MTI) blog.
However, upon closer inspection, the researchers realized that GigaWiper combines separate malware families and gives attackers flexibility to choose how they can destroy a system via on-demand backdoor commands once they've established control of the victim network.








