Microsoft Warns of GigaWiper Backdoor Built to Destroy Windows PCs
2026-07-10T08:51:41Z•992cbcdaeef6ca655aa6cc26dd49889c9b62cfc6c30d81efde52283bc933c4e9
ai-coding-assistantsamazon-bedrockaptarmored-likhobackdoorbusysnakecryptominingdestructive-malwareghostapprovalgigawiperliteLLMphishingroundcubesecurity-advisoryssh-exposurestealersupply-chainsymlink-vulnerabilitytargeted-attacksuniversitiesunk_masstractionwindowswiper
What happened
Multiple high-risk incidents reported: Microsoft disclosed GigaWiper, a destructive Windows backdoor able to wipe disks, encrypt files, and provide remote access — posing an immediate high-impact risk to Windows endpoints. Separately, an AI gateway using LiteLLM linked to Amazon Bedrock was hijacked for cryptomining after exposed SSH activity. Wiz disclosed “GhostApproval” symlink flaws in major AI coding assistants that can hide targets, bypass approval checks and enable workspace escape and potential system access. Kaspersky detailed Armored Likho APT using BusySnake stealer and AI-generated
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- 992cbcdaeef6ca655aa6cc26dd49889c9b62cfc6c30d81efde52283bc933c4e9
- Enrichment time
- 2026-07-10T08:51:41Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.