BiBi-Linux
- Malware type
- wiper
- Profile updated
- 2026-07-07 13:10:44
Context
According to Security Joes, this malware is an x64 ELF executable, lacking obfuscation or protective measures. It allows attackers to specify target folders and can potentially destroy an entire operating system if run with root permissions. During execution, it produces extensive output, which can be mitigated using the "nohup" command. It also leverages multiple threads and a queue to corrupt files concurrently, enhancing its speed and reach. Its actions include overwriting files, renaming them with a random string containing "BiBi," and excluding certain file types from corruption.
Reports & references
- securityjoes.com — Bibi Linux A New Wiper Dropped By Pro Hamas Hacktivist Group (report)
- research.checkpoint.com — Bad Karma No Justice Void Manticore Destructive Activities In Israel (report)
- malpedia.caad.fkie.fraunhofer.de — Elf.Bibi Linux (report)
- securityjoes.com — Mission Data Destruction A Large Scale Data Wiping Campaign Targeting Israel (report)