GigaWiper, A new and dangerous piece of Windows malware has been uncovered that can spy on victims, take control of their PC, and permanently erase every file.
Most malware tends to have one objective, whether that’s stealing passwords, encrypting files for a ransom, or quietly mining cryptocurrency with your PC’s resources. GigaWiper is new and different. Not content with focusing on one form of damage, it ups its game by using multiple attack methods. It’s also very stealthy. Microsoft security researchers first spotted it in October 2025, but it’s kept a relatively low profile since then. This is because the creators of GigaWiper have put significant resources into making it so powerful.
A Swiss Army Knife of Attacks
GigaWiper is a backdoor, a type of malware which discreetly opens a “backdoor” into your PC for someone else to control it remotely. Once in, the attacker has free rein to carry out all kinds of digital chaos. From recording your screen in real-time to controlling your hardware and harvesting system data, GigaWiper can do it all. One of its ingenious techniques is to disguise one of its most persistent tricks as a OneDrive update.
At first, the attackers lie low, ensuring that the victim’s defenses are down. But when GigaWiper kicks into gear, it does it dramatically with three main attacks:
- GigaWiper’s first technique starts directly overwriting the PC’s hard drive in large sections at a time. This renders any recovery attempts next to impossible.
- Next up is a particularly sneaky attack in which GigaWiper pretends to be ransomware. Appearing to encrypt your files, it demands a payment to release them. However, it instantly throws away the decryption key, meaning that payment results in nothing.
- The final method puts Windows in the crosshairs of GigaWiper. Running multiple passes over the infected drive with different patterns, GigaWiper makes sure that nothing can ever be recovered.
What’s unique about GigaWiper is that it’s not interested in making money or causing temporary disruption. Instead, it wants to destroy PCs and leave nothing behind.
Can You Stop GigaWiper?
A new strain of malware is always worrying, but GigaWiper has intentionally set destructive power high – this is what makes it so concerning. But you can reduce your risk with Ophtek on your side. GigaWiper is believed to get into systems through an initial compromise. Accordingly, stopping that first breach is crucial. You can do that by practicing the following:
- Keep security software updated: security breaches are always minimized when your security software is up to date, ensuring that it can protect you against all the latest threats. And make sure tamper protection is switched on. This stops malware from disabling your defenses.
- Always be cautious online: unsolicited emails, downloads, and remote access requests should always be treated with suspicion. Malware needs a way in, and phishing emails or compromised credentials are the simplest ways for it to get in.
- Backups are essential: if you want to retain access to all your files, make sure they’re regularly backed up. In the event of your files being deleted or encrypted, a backup provides a critical safety net. If you want to know where to start with backups, the 3-2-1 method is our recommended approach.
For more ways to secure and optimize your business technology, contact your local IT professionals.




