BiBiGun

First seen
2023-09-01 00:00:00
Origin
PS
Primary motivation
sabotage
Sophistication
intermediate
Resource level
team
Actor type
hacktivist
Profile updated
2026-07-07 12:11:07

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:il

Context

A pro-Hamas hacktivist group developed a wiper called BiBi-Linux to target and destroy data on Israeli systems. The malware impersonates ransomware but operates solely to corrupt and delete files, indicating no data theft. A Windows variant, BiBi-Windows, was also discovered, sharing similarities with BiBi-Linux but targeting all files except executables. ESET researchers have named the group behind the wipers BiBiGun. The group's TTPs have shown overlaps with Moses Staff, which is believed to have an Iran nexus.

Reports & references

  • twitter.com — 1719437301900595444 (report)
  • github.com — Bibi Windows Wiper Analysis (report)
  • thehackernews.com — New Bibi Windows Wiper Targets Windows (report)
  • securityjoes.com — Bibi Linux A New Wiper Dropped By Pro Hamas Hacktivist Group (report)

External references