Microsoft Warns of GigaWiper Backdoor Built to Destroy Windows PCs

2026-07-10T08:51:41Z992cbcdaeef6ca655aa6cc26dd49889c9b62cfc6c30d81efde52283bc933c4e9
ai-coding-assistantsamazon-bedrockaptarmored-likhobackdoorbusysnakecryptominingdestructive-malwareghostapprovalgigawiperliteLLMphishingroundcubesecurity-advisoryssh-exposurestealersupply-chainsymlink-vulnerabilitytargeted-attacksuniversitiesunk_masstractionwindowswiper

What happened

Multiple high-risk incidents reported: Microsoft disclosed GigaWiper, a destructive Windows backdoor able to wipe disks, encrypt files, and provide remote access — posing an immediate high-impact risk to Windows endpoints. Separately, an AI gateway using LiteLLM linked to Amazon Bedrock was hijacked for cryptomining after exposed SSH activity. Wiz disclosed “GhostApproval” symlink flaws in major AI coding assistants that can hide targets, bypass approval checks and enable workspace escape and potential system access. Kaspersky detailed Armored Likho APT using BusySnake stealer and AI-generated

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hackread
Record identifier
992cbcdaeef6ca655aa6cc26dd49889c9b62cfc6c30d81efde52283bc933c4e9
Enrichment time
2026-07-10T08:51:41Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.