Get all your news in one place.
100's of premium titles.
One app.
Start reading
PC Gamer
PC Gamer
Andy Edser

Meet GigaWiper, a tricksy new malware that can wipe your PC's storage drives squeaky clean and spy on your desktop all at once

A cleaner standing in front of a house.

I run a single SSD gaming PC, which I'm aware is giving me a wonderful case of 'single-point-of-failure-itus.' Which is why my ears (eyes?) perked up when I read about GigaWiper, a wonderfully-named malware that can potentially do terrible things to your storage drives.

Microsoft has published an analysis into GigaWiper's capabilities, and it looks to be a multi-faceted, tricksy piece of malware with a pretty unique USP (via MalwareBytes). It appears to be the result of several malware families stitched together, and is capable of wiping your drives at the physical disk level, "overwriting raw disk content and removing partition metadata."

The nasty little beastie has several ways to irreversibly destroy your data. There's a Windows drive secure wiper for starters, which targets an installation and performs multiple overwrites using different byte patterns, making the original data virtually impossible to retrieve.

Another method identifies physical disk drives, confirms which drive contains a Windows installation, removes the partition references from your other drives, overwrites the raw disk content with randomized data, and reboots your system for good measure.

Keep your fork, there's more. Another Crucio-based wiper imitates traditional ransomware, but instead of demanding payment, encrypts your files and then "throws away the encryption key" instead, according to MalwareBytes.

(Image credit: Pixabay (Elchinator))

GigaWiper's all-in-one approach also means it's capable of capturing your screen, streaming your desktop, and allowing remote control of your machine via an outside TCP server, all while hiding itself under the cover of a scheduled OneDrive task. Jolly good.

The good news for us home PC users is that GigaWiper seems to be targeted towards organisations rather than individual machines, and can only operate after breaching a PC in the first place—so the usual "keep your security software updated" advice should be enough for the majority.

For sysadmins, though, Microsoft recommends multiple network-hardening methods (including "tenant-wide tamper protection") to stop breaches before they occur. This is one piece of Malware you really don't want running rampant through your IT infrastructure, so I'd take this as yet another reason to have a thorough review of your security practices.

Sign up to read this article
Read news from 100's of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.