Microsoft Threat Intelligence identified a modular malware family that can collect intelligence, maintain remote access, and switch to destructive wiping on command.
The destructive malware described here stands out because it bundles several impact modes into one implant, letting operators switch between wiping and encryption rather than relying on a single blunt tool.
A Golang-based malware family is reported to use a OneDrive-themed scheduled task for persistence, showing how ordinary Windows maintenance patterns can be repurposed for destructive operations.
Microsoft’s warning points to a troubling hybrid: a Go-based backdoor that can keep a foothold, collect data, and pivot into destructive action against Windows systems.