• About WordPress
    • WordPress.org
    • Documentation
    • Learn WordPress
    • Support
    • Feedback
  • Log In
  • Register

AnonymousMedia.org

  • Home
  • Headline News
  • Videos
  • Chat
  • History
  • File Manager
  • Activity
  • Forums
  • New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware

    New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware


    Microsoft has taken apart a destructive Windows backdoor it calls GigaWiper. What stands out is how it is built: not one tool but three older destructive programs bolted into one, offered as commands the operator can choose from.

    Each is a different way to break a machine: wipe the whole disk, overwrite the Windows drive, or run fake “ransomware” that scrambles files with a key it never saves.

    Because this is malware and not a single flaw, there is no patch to chase; GigaWiper is what an attacker runs after they are already inside, which makes early detection and clean, offline backups the real defense.

    The same malicious files show up in a second report under another name: BLUERABBIT, a backdoor Binary Defense flagged last month.

    Cybersecurity

    Microsoft lists four hashes for the GigaWiper backdoor; Binary Defense lists the same four for BLUERABBIT, and both command servers match. Binary Defense, citing Google’s Threat Intelligence Group, ties the malware to a likely Iran-nexus group aimed at Israeli organizations. Microsoft names no country.

    Three ways to destroy a machine

    GigaWiper is written in Go (also called Golang) and runs on Windows. It takes orders as numbered commands, and three of them destroy the machine, each in a different way:

    • A raw disk wiper that overwrites the physical drive and wipes the partition table (the map of how the disk is laid out) before rebooting. There is no file-by-file deletion to reverse; it destroys the disk contents directly.
    • Fake ransomware built on older code called Crucio. It encrypts files, adds a .candy extension, and changes the desktop wallpaper to an alarming warning image. There is no ransom note and no saved key, so there is nothing to pay and nothing to decrypt. This is destruction wearing a ransomware costume.
    • The last targets the Windows drive, overwriting it several times with different data patterns. Microsoft says it is a Go rewrite of a wiper it tracks as FlockWiper.

    None of these leaves a way back: encrypted files cannot be unlocked because the key is gone, and wiped drives can only be rebuilt from clean backups. The goal is a dead machine, not a payout.

    It spies, too

    Destruction is only half of it. The same backdoor can quietly watch and control an infected PC. It takes screenshots of every monitor, records the screen while someone is working, and can open a hidden VNC session that streams the display and lets the attacker type and move the mouse.

    It also collects system details, manages running programs and services, edits the registry, and can wipe Windows event logs to cover its tracks. Microsoft found more commands sitting dormant in the samples it examined, including stubs for a keylogger and additional wipers.

    To stay out of sight, GigaWiper pretends to be OneDrive. It creates a scheduled task named OneDrive Update that runs every minute and tracks itself in a registry key under HKCU\SOFTWARE\OneDrive\Environment. When it opens its remote-control channel, it hides behind a firewall rule named after a real Windows component, Microsoft.Windows.CloudExperienceHost.

    For its command traffic, it skips ordinary web requests and rides on real business services instead: RabbitMQ for tasking, Redis for results, and MinIO for exfiltration. Because those are legitimate tools rather than a custom malware channel, the traffic looks ordinary on networks that already run them.

    Where GigaWiper came from

    Microsoft traces GigaWiper’s fake-ransomware code back to Crucio and its multi-pass wiper back to FlockWiper, and assesses that the same developer built all three. It names no country. But Crucio is not anonymous. Its code was listed as suspected ransomware in a December 2023 CISA advisory on CyberAv3ngers, a group linked to Iran’s Islamic Revolutionary Guard Corps.

    That is the same crew, THN reported, that broke into water and energy sites across the US, Israel, the UK, and Ireland in 2023, logging into internet-exposed industrial controllers. In one case, they took control of a booster station at a Pennsylvania water authority. The Crucio sample Microsoft cites carries the same fingerprint listed in that advisory.

    Microsoft also found a recurring tag, “GRAT”, in both FlockWiper’s debug paths and GigaWiper’s own function names, tying the two tools together and hinting at a further component that has not surfaced yet. The timing differs by source: Microsoft dates the destructive activity to October 2025, while Binary Defense first saw the same files as BLUERABBIT in March 2026.

    Part of a bigger wave

    Iran-linked wiper activity against Israel has drawn repeated warnings through 2025 and 2026. Palo Alto Networks’ Unit 42 has tracked a parallel surge, much of it from a separate group, Handala Hack, and in March 2026 Israel’s National Cyber Directorate warned of Iranian wiper attacks on local organizations.

    The tactic GigaWiper uses is old: NotPetya in 2017 also posed as ransomware while quietly destroying data. The disguise buys the attacker time: a wrecked machine first looks like a ransomware case someone might recover from, not the total loss it is.

    Microsoft frames GigaWiper as operators folding separate tools into one flexible platform. For defenders, the consequence is concrete: when a single implant can watch, steal, or destroy, the tool no longer reveals the goal. You used to read intent from the malware you found; here, the operator decides after they are already inside.

    Cybersecurity

    One platform, two vendor names, and dormant command stubs still in the code point to a tool still being built out.

    What defenders should do

    Spotting it fast comes down to a few specific signals:

    • A OneDrive Update scheduled task that repeats every minute.
    • RabbitMQ or Redis traffic from ordinary desktops rather than servers.
    • Processes using takeown and icacls to take ownership of Windows boot files like bootmgr and ntoskrnl.exe outside maintenance windows.

    On the product side, Microsoft recommends turning on tamper protection so attackers cannot switch off your antivirus, blocking the two known command servers (185.182.193[.]21 and 212.8.248[.]104), running endpoint detection in block mode, and enabling cloud-delivered protection and automatic remediation. The full list of file hashes, server addresses, and detection names is in Microsoft’s report.

    The Hacker News has reached out to Microsoft and to Binary Defense for confirmation that GigaWiper and BLUERABBIT are the same malware, and for details on victim scope and attribution, and will update this story with any response.



    Source link

    07/09/2026
  • Bari Weiss Is Filling CBS News With British Right Wing Propagandists

    Bari Weiss Is Filling CBS News With British Right Wing Propagandists


    from the you’re-simply-not-very-good-at-anything dept

    Bari Weiss is seeking out friendly interviewers at the New York Times to try and “calm the firestorm engulfing her leadership of CBS News.” By “leadership” of course they mean censoring stories critical of the president, letting Benjamin Netanyahu pick his own interviewer (who he knows won’t press him on war crimes), firing a bunch of industry veterans, and just generally being an unqualified, fail-upward clod.

    As we’ve long explored, Weiss wasn’t hired to do journalism. She was hired to do right wing agitprop. But given she’s not good at that either, CBS just saw its lowest ratings in a quarter century.

    Undaunted, Weiss is continuing her efforts to “reshape” CBS into something Larry Ellison and other U.S. oligarchs approve of. As a result she’s apparently accelerated efforts to hire a bunch of right wing Brits, most of them with associations to Rupert Murdoch’s sprawling right wing tabloid empire. Said Brits will, curiously enough, tell you that hiring a bunch of white right wing Brits is a wonderful idea:

    “According to several figures familiar with her thinking, however, the hires are no coincidence. “She’s been looking at various Brits that might add a bit of opinion/attitude diversity to US media, instead of the dominant, predictable Columbia Journalism School uniformity. Not a bad idea,” said Andrew Neil, the former editor of Rupert Murdoch’s Sunday Times, who supported her hiring of Phillips.”

    Hiring a bunch of white male right wing protectors of the extraction class (and global autocrats) as the pinnacle of “opinion diversity” is a theme you’ll see constantly throughout Weiss’ demolition and repurposing of CBS. Because said British tabloiders sometimes break gossip on politicians and celebrities (often illegally) they’re framed as tough journalists:

    “A CBS News source, describing Weiss’s interest in British journalists, said: “They do the kind of things that Bari is looking for; it’s not puff pieces and kid gloves.”

    Rupert Murdoch’s longstanding skill wasn’t just to make right wing propaganda, but right wing propaganda that entertained and drew ratings and subscriptions. A soup of agitprop infotainment. To date there’s absolutely zero indication that Weiss and Ellison have any knack for that whatsoever, so they’re attempting to hire Rupert Murdoch adjacent folks who do.

    Even then, it’s no longer the same world Rupert Murdoch thrived in. Broadcast TV is dying, social media is ever evolving, and (as we’ve seen at outlets like the Jeff Bezos Washington Post), people aren’t really in the mood for right wing billionaire simping agitprop. With any luck, the “new” CBS will collapse under the load of Warner Bros debt long before Weiss and company figure out the right formula.

    Filed Under: bari weiss, consolidation, journalism, media, news, propaganda, rupert murdoch

    Companies: cbs, paramount



    Source link

    07/09/2026
  • Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs

    Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs


    Ravie LakshmananJul 09, 2026Developer Security / Supply Chain Security

    Datadog Security Labs is warning of “several overlapping campaigns” that are systematically enumerating corporate GitHub organizations, repositories, and user accounts through the GitHub API.

    “Operators rely on automated scraping tooling with custom or legitimate-sounding user agents, leveraging GitHub ‘ghost’ accounts that are often years old, or compromised OAuth tokens and personal access tokens (PATs) from legitimate users,” Julie Agnes Sparks, senior security engineer at Datadog, said.

    While the activity in most cases involves targeting public data, select instances have gone beyond public information enumeration to successfully clone private repositories.

    The campaign employs a mix of automated scanner tools, over 50 dormant accounts, and dozens of legitimate accounts that have had their personal access tokens (PATs) exposed unintentionally or compromised through some other method to facilitate the enumeration.

    Cybersecurity

    What’s notable about the “ghost” accounts is that they were created two to five years ago and intentionally left inactive for extended periods of time before weaponizing them to issue API traffic across multiple organizations. This technique is strategic as it aims to avoid raising any red flags and pass off the activity as legitimate, as opposed to creating new accounts and immediately using them for scraping.

    Because a large chunk of GitHub’s API surface is reachable without authentication, the enumeration queries return the necessary data, while blending into normal API usage. Some of them include –

    • Listing an organization’s public repositories
    • Walking a user’s followers and following lists
    • Enumerating gists, starred repos, and org memberships, and
    • Running GraphQL queries against public objects

    This information can be used by a threat actor to conduct reconnaissance and programmatically map out an organization’s GitHub-related activity, such as its public repositories, its members, who those members follow, and which projects they modify.

    Data access has been confirmed in a few scenarios, with the attackers taking steps to clone a private repository belonging to a single organization.

    “Individually, most of these requests are unremarkable. They hit public endpoints, authenticate cleanly or not at all, and return successful responses,” Datadog said. “The concern lies in the aggregate: a group of accounts moving in sync across companies’ GitHub organizations with versioned custom tooling iterating over weeks, and in the worst case, actors that stopped enumerating and started cloning.”



    Source link

    07/09/2026
1 2 3 … 1,030
Next Page→