BiBi-Linux Wiper: New Malware Targets Israeli Companies Amidst Conflict
- Actor Motivations: Sabotage
- Attack Vectors: Wiper
- Attack Complexity: Medium
- Threat Risk: High Impact/Low Probability
Threat Overview
The Security Joes team discovered a new Linux Wiper malware, dubbed BiBi-Linux Wiper, used by a pro-Hamas hacktivist group during the conflict between Israel and Hamas. This malware, an x64 ELF executable, is designed to destroy systems by overwriting and renaming files, particularly targeting Israeli companies. It lacks obfuscation, utilizes multi-threading for efficiency, and avoids corruption of certain file types crucial for its operation. The term "BiBi" in the malware's naming convention is a political reference to Israeli Prime Minister Benjamin Netanyahu, suggesting a targeted political motive behind the attacks.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Region | Israel | Verified |
Extracted IOCs
- 23bae09b5699c2d5c4cb1b8aa908a3af898b00f88f06e021edcb16d7d558efad
Tip: 1 related IOCs (0 IP, 0 domain, 0 URL, 0 email, 1 file hash) to this threat have been found.
Overlaps
Source: Security Joes - November 2023
Detection (one case): 23bae09b5699c2d5c4cb1b8aa908a3af898b00f88f06e021edcb16d7d558efad
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
BiBi-Linux Wiper
During the war between Israel and Hamas, security responders discovered a new destructive malware called BiBi-Linux Wiper. This malware was deployed to corrupt corporate files and possesses the capability to destroy entire operating systems.
The attack was carried out by a Pro-Hamas (MOIS linked) hacktivist group.
The primary goal of the attack is absolute data destruction. Instead of encrypting data to demand a ransom, the malware renders files completely unusable by replacing their original contents with random junk data.
Yes, the malware specifically targeted Israeli companies.
Attackers deployed the wiper malware onto targeted machines and used specific system commands to hide the program's noisy output so it could run undetected. The malware then used multiple threads to rapidly overwrite target files with random data and rename them, deliberately skipping certain critical system files so the computer wouldn't crash before the destruction was complete.
Israeli companies were attractive targets due to the ongoing wartime conflict between the state of Israel and the terrorist organization Hamas. The malware also features a hardcoded political reference to the Israeli Prime Minister, highlighting a strong ideological motivation behind the targeting.
Organizations must strictly control root (administrator) access, as the malware needs it to destroy an entire operating system. Additionally, defenders should actively monitor for the specific malicious file named "bibi-linux.out" and watch for unusual file renaming activity involving the word "BiBi".
This is a highly targeted issue. The attacks were directed specifically at Israeli companies by hacktivists during a period of severe geopolitical conflict.