GigaWiper is a sophisticated Golang-based backdoor discovered by Microsoft Threat Intelligence in October 2025 that amalgamates at least three previously separate malware families — a standalone disk wiper, Crucio ransomware, and FlockWiper — into a single modular implant with 20 commands. It uses RabbitMQ and Redis for C2 communication, establishes persistence via scheduled tasks, and offers capabilities including disk wiping, fake ransomware (with unrecoverable encryption), BSOD induction, screen recording, keylogging, registry management, event log clearing, and VNC-like remote control. The malware masquerades as legitimate Windows components (OneDrive Update, CloudExperienceHost) and uses AES-encrypted configurations with hard-coded credentials.
Backdoor
7 posts
GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure CL-STA-1062, a Chinese-speaking threat cluster assessed to be the same as UAT-7237, has compromised Southeast Asian government and critical energy infrastructure entities throughout 2025 using web shell deployment, MSSQL data exfiltration, and open-source tunneling tools (SoftEther VPN, VNT, yuze). The group has introduced TinyRCT, a previously undocumented .NET backdoor delivered via AppDomainManager Injection (malicious chrome_setup.zip), which uses AES-CBC encrypted HTTP C2, sandbox-evasion path checks, scheduled-task persistence disguised as legitimate updater services, and a self-destruct routine using choice.exe for anti-forensic file deletion.
Dozens of malicious wallpapers found on Steam Workshop: gamers’ accounts at risk Cybercriminals are abusing the 'application wallpapers' feature of Wallpaper Engine on Steam Workshop to distribute malware, including DarkKomet, Lumma, and Vidar. The malicious wallpapers drop backdoors and patched system libraries to hijack active Steam sessions, primarily targeting gamers in China and Russia.
APT Meets GPT: Targeted Operations with Untamed LLMs The China-aligned threat actor UTA0388 is leveraging Large Language Models (LLMs) to conduct highly tailored, rapport-building spear-phishing campaigns targeting organizations in North America, Asia, and Europe. These campaigns deliver GOVERSHELL, a custom backdoor deployed via DLL search order hijacking, which has undergone rapid, non-iterative development across five variants to evade detection and establish persistent C2.
Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware Void Dokkaebi has updated its InvisibleFerret malware by compiling the original Python scripts into Cython binaries (.pyd for Windows, .so for macOS) to evade traditional script-based detection. The campaign utilizes a multi-stage BeaverTail JavaScript infection chain to deliver these binaries, targeting software developers to steal cryptocurrency wallet credentials, establish backdoor access, and downgrade browser security controls.
FIRESTARTER Backdoor CISA and NCSC identified FIRESTARTER, a persistent Linux ELF backdoor deployed by APT actors on Cisco Firepower and Secure Firewall devices. The malware hooks into the LINA engine, survives firmware updates and soft reboots, and facilitates the deployment of secondary payloads like LINE VIPER to establish unauthorized VPN sessions.
CanisterWorm: npm Publisher Compromise Deploys Backdoor Across 29+ Packages CanisterWorm is a worm-enabled supply chain attack that compromises legitimate npm publisher accounts to distribute a Python backdoor. The malware establishes user-level Linux persistence via systemd and utilizes an Internet Computer Protocol (ICP) canister as a dead-drop C2 to continuously fetch and execute secondary payloads, while simultaneously harvesting npm tokens to propagate itself to other packages.