Threats Feed|Karma|Last Updated 05/05/2026|AuthorCertfa Radar|Publish Date30/10/2023

BiBi-Linux Wiper: New Malware Targets Israeli Companies Amidst Conflict

  • Actor Motivations: Sabotage
  • Attack Vectors: Wiper
  • Attack Complexity: Medium
  • Threat Risk: High Impact/Low Probability

Threat Overview

The Security Joes team discovered a new Linux Wiper malware, dubbed BiBi-Linux Wiper, used by a pro-Hamas hacktivist group during the conflict between Israel and Hamas. This malware, an x64 ELF executable, is designed to destroy systems by overwriting and renaming files, particularly targeting Israeli companies. It lacks obfuscation, utilizes multi-threading for efficiency, and avoids corruption of certain file types crucial for its operation. The term "BiBi" in the malware's naming convention is a political reference to Israeli Prime Minister Benjamin Netanyahu, suggesting a targeted political motive behind the attacks.

Detected Targets

TypeDescriptionConfidence
RegionIsrael
Verified

Extracted IOCs

  • 23bae09b5699c2d5c4cb1b8aa908a3af898b00f88f06e021edcb16d7d558efad
download

Tip: 1 related IOCs (0 IP, 0 domain, 0 URL, 0 email, 1 file hash) to this threat have been found.

Overlaps

KarmaBiBi Wiper: A Politically Charged Cyberattack Targets Israeli Defense and Data Sectors

Source: Security Joes - November 2023

Detection (one case): 23bae09b5699c2d5c4cb1b8aa908a3af898b00f88f06e021edcb16d7d558efad

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

BiBi-Linux Wiper

During the war between Israel and Hamas, security responders discovered a new destructive malware called BiBi-Linux Wiper. This malware was deployed to corrupt corporate files and possesses the capability to destroy entire operating systems.

The attack was carried out by a Pro-Hamas (MOIS linked) hacktivist group.

The primary goal of the attack is absolute data destruction. Instead of encrypting data to demand a ransom, the malware renders files completely unusable by replacing their original contents with random junk data.

Yes, the malware specifically targeted Israeli companies.

Attackers deployed the wiper malware onto targeted machines and used specific system commands to hide the program's noisy output so it could run undetected. The malware then used multiple threads to rapidly overwrite target files with random data and rename them, deliberately skipping certain critical system files so the computer wouldn't crash before the destruction was complete.

Israeli companies were attractive targets due to the ongoing wartime conflict between the state of Israel and the terrorist organization Hamas. The malware also features a hardcoded political reference to the Israeli Prime Minister, highlighting a strong ideological motivation behind the targeting.

Organizations must strictly control root (administrator) access, as the malware needs it to destroy an entire operating system. Additionally, defenders should actively monitor for the specific malicious file named "bibi-linux.out" and watch for unusual file renaming activity involving the word "BiBi".

This is a highly targeted issue. The attacks were directed specifically at Israeli companies by hacktivists during a period of severe geopolitical conflict.

About Affiliation
Karma
Karma is an Iranian-linked hacktivist persona active since at least 2022, conducting hack-and-leak and defacement operations targeting Israeli organizations. The group publishes stolen data via Telegram and claims responsibility for intrusions into Israeli companies, using the persona to create psychological pressure while maintaining plausible deniability for the Iranian state. Karma operations share timing, targeting, and operational patterns with other Iran-linked personas active during the same period, including Handala and Cyber Toufan, suggesting a coordinated broader Iranian influence and disruption campaign against Israel.
View Karma's Insights