Skip to content
← All Threat Actors
Cybercrime high Iran

Iran-nexus (GigaWiper/BLUERABBIT)

Iran-nexus (Microsoft and Binary Defense/Google TIG — assessed IRGC or MOIS affiliated) · Destructive attacks against Israeli organisations / psychological operations / retaliation for US-Iran military engagement

Reports 1
Active Since 2025
Last Reported 12 Jul 2026
Sectors Targeted critical-infrastructure, healthcare, communications

Tactics, Techniques & Procedures (TTPs)

  • GigaWiper / BLUERABBIT modular Go-based backdoor: three destructive modes invokable remotely — raw disk wipe, fake ransomware (Crucio-derived, no recoverable key), and file encryption with wallpaper change
  • Raw disk wipe: overwrites physical drive content and partition metadata before forcing reboot — drive is unreadable on restart, no file-by-file recovery possible
  • Fake ransomware (.candy extension): encrypts files with no key generation, presents all ransomware visual signals as a ruse to obscure destructive intent — ransom payments yield no decryption
  • Live spyware module: screen capture, audio recording, keystroke logging, file exfiltration — runs silently alongside destructive modules
  • Assembled from multiple pre-existing malware families rather than purpose-built — rapid capability composition approach
  • Targets Windows environments; deployment via existing footholds in Israeli organisational infrastructure
  • Operations temporally correlated with US-Iran military engagement (Operation Epic Fury, February 2026 onwards)

Known Targets

Israeli government organisationsIsraeli healthcare sectorIsraeli communications infrastructureIsraeli private sector organisationsOrganisations in sectors perceived as supporting Israeli or US military operations

Analyst Notes

GigaWiper / BLUERABBIT was publicly documented in July 2026 by Microsoft Threat Intelligence and separately under the BLUERABBIT designation by Binary Defense and Google TIG (March 2026). The fake ransomware component is the most tactically significant element: by presenting all ransomware indicators (encrypted files, changed wallpaper, ransom note format) without generating a recoverable key, the operator confuses incident response, triggers the wrong playbook, and may extract ransom payments while providing no possibility of decryption. This tactic mirrors MuddyWater's Chaos ransomware false flag, suggesting Iranian state cyber actors share doctrine on deception-via-criminal-branding. The modular assembly approach — building from existing malware families — allows rapid capability deployment without bespoke malware development cycles. Attribution to a specific named Iranian group has not been publicly confirmed; operation timing and targeting aligns with the Iran-Israel conflict dynamics and the broader MOIS/IRGC ecosystem.

Also Known As

GigaWiper (Microsoft designation)BLUERABBIT (Binary Defense / Google TIG designation)Relationship to Handala operations assessed but not confirmed