Back to Blog
Weekly CISO Digest — Week of 2026-07-13: GigaWiper Backdoor Destructive Surge
security-guides

Weekly CISO Digest — Week of 2026-07-13: GigaWiper Backdoor Destructive Surge

breachwire TeamJul 13, 20264 min read

Headline Incident: GigaWiper backdoor malware detected in confirmed intrusions targeting multiple victims

Microsoft identified GigaWiper, a modular Golang backdoor first seen in October 2025, now confirmed in active intrusions against multiple unnamed victims globally. GigaWiper combines remote administration, disk wiping, and ransomware capabilities with no recovery possible, consolidating code from Crucio and FlockWiper families. The malware can selectively destroy victim data on command and leverages command-and-control infrastructure using RabbitMQ and Redis endpoints. Microsoft released IOCs, including FlockWiper and Crucio file hashes and specific C2 IPs, along with mitigation guidance for defenders. All organizations should review endpoint hardening, monitor for listed IOCs, and update detection rules immediately.

This Week's Incidents

Attackers Exploit Ill Bloom Vulnerability to Drain Over $5 Million From Cryptocurrency Wallets

What: Coinspect disclosed a critical flaw in wallet recovery phrase generation, exploited on May 27, 2026, to steal over $5 million from 432 wallets.
Who's at risk: Cryptocurrency wallet providers and users with weak entropy implementations.
Action: Audit wallet generation code and rotate affected recovery phrases immediately.

DHS Database Breached by Unidentified Threat Actor

What: The Homeland Security Information Network (HSIN) was breached, targeting servers and SharePoint infrastructure for interagency communication.
Who's at risk: US federal agencies using HSIN and connected systems.
Action: Review access logs, isolate affected systems, and enhance monitoring for lateral movement.

Ryuk Ransomware Member Pleads Guilty Over Attacks on U.S. Organizations

What: Karen Serobovich Vardanyan admitted to deploying Ryuk ransomware against Michigan, Oregon, and Texas organizations, encrypting hundreds of systems.
Who's at risk: US companies in critical infrastructure, education, and technology sectors.
Action: Validate ransomware response plans and ensure offline, tested backups.

US Security Expert Sentenced for Assisting BlackCat Ransomware Gang

What: Angelo Martino, a former US ransomware negotiator, was sentenced to 70 months for providing BlackCat/Alphv with confidential victim negotiation data to maximize extortion.
Who's at risk: Any organization using third-party ransomware negotiators.
Action: Vet all external negotiators and restrict access to sensitive negotiation data.

Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Due to Credible Security Threat

What: Progress Software warned ShareFile Storage Zone Controller customers to immediately disconnect internet-facing Windows servers due to CVE-2023-24489.
Who's at risk: All ShareFile Storage Zone Controller customers globally.
Action: Take affected servers offline and apply vendor mitigation guidance.

AssuranceAmerica Breach Exposes 7 Million Driver’s Licenses

What: An employee account compromise at AssuranceAmerica led to the exposure of 7 million driver’s license records.
Who's at risk: US insurance sector and affected individuals.
Action: Notify impacted individuals and review employee account security controls.

Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers

What: A vishing campaign since April 2026 targets Microsoft 365 customers, registering attacker-controlled passkeys for persistent access and extortion.
Who's at risk: Microsoft 365 customers across automotive, aviation, construction, healthcare, and technology.
Action: Monitor for suspicious passkey registrations and educate users on vishing tactics.

Multi-Group Cyber Espionage Campaign Targets Balochistan Police Portal

What: China- and India-aligned APTs compromised Pakistani police web apps, deploying PlugX, ShadowPad, Cobalt Strike, and Remcos RAT for espionage.
Who's at risk: Law enforcement and government agencies in Pakistan and neighboring regions.
Action: Audit web application security and hunt for known APT malware IOCs.

Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer

What: The jscrambler npm package v8.14.0 was trojanized, installing a Rust-based infostealer on developer machines across Windows, macOS, and Linux.
Who's at risk: Developers and organizations using jscrambler@8.14.0.
Action: Remove the compromised package, rotate developer credentials, and scan for listed hashes.

Operation Muck and Load: Network of 200 GitHub Repositories Used for Malware Infection

What: Over 200 GitHub repositories distributed Windows malware via malicious Go modules, delivering spyware, RATs, and cryptominers since January 2026.
Who's at risk: Developers and organizations relying on public GitHub modules.
Action: Review dependencies for suspicious modules and enforce code provenance checks.

US Security Expert Sentenced for Assisting BlackCat Ransomware Gang

What: Angelo Martino, ex-negotiator, received 70 months for aiding BlackCat/Alphv ransomware, sharing confidential data to increase ransom demands.
Who's at risk: US organizations relying on external ransomware negotiation.
Action: Reassess trust and access controls for third-party negotiators.

Florida ransomware negotiator convicted for aiding BlackCat ransomware gang

What: Martino conspired with BlackCat to extort US companies, including Change Healthcare, laundering at least $1.2 million in ransom proceeds.
Who's at risk: US healthcare and corporate ransomware victims.
Action: Investigate past negotiations for insider risk and update incident response protocols.

Ransomware Negotiator Sentenced for Aiding BlackCat Attacks

What: Martino, a former negotiator, was sentenced for colluding with BlackCat to extort multiple US victims, betraying client trust.
Who's at risk: DigitalMint, Sygnia, and other US ransomware victims.
Action: Audit all negotiation engagements for signs of insider collusion.

GigaWiper Windows backdoor malware capable of wiping systems

What: Microsoft detailed GigaWiper, a modular Golang backdoor for Windows with disk wiping, ransomware, and remote access features.
Who's at risk: Any Windows endpoint globally, especially those lacking recent security updates.
Action: Monitor for GigaWiper IOCs (e.g., 185.182.193.21, 212.8.248.104) and enforce endpoint hardening.

This Week's Pattern

  • Insider threat and third-party risk surged, with three separate cases of ransomware negotiators aiding BlackCat/Alphv, highlighting the need for strict vetting and access controls.
  • Supply chain attacks escalated, including the jscrambler npm compromise and Operation Muck and Load on GitHub, targeting developer ecosystems with infostealers and malware.
  • Destructive malware and advanced APT campaigns (GigaWiper, Balochistan Police espionage) increased, signaling a shift toward irreversible data loss and persistent espionage, demanding enhanced detection and response readiness.

Start Your 14-Day Free Trial

Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.

Get Started Free
Share this article: