logo

BiBi Wiper Used in the Israel-Hamas War Now Runs on Windows

ID: 414b5036-f960-58f9-b864-6f550a053360

STIX ID: report--414b5036-f960-58f9-b864-6f550a053360

Feed Name: Arctic Wolf Blog

Threat Score
75/100

Date Published: 2023-11-10

Date Updated: 2026-04-27

...
...

Arctic Wolf Labs reports on a BiBi-Windows wiper, a x64 Visual Studio 2019-compiled PE linked to pro-Hamas hacktivists and a previously reported Linux variant; the malware overwrites most user files with random bytes, renames them with a .BiBi[number] extension, deletes shadow copies, disables Windows recovery mechanisms, uses RTL-obfuscated CMD strings to evade simple detections, leverages Restart Manager to ensure completion, and includes provided IOCs and a YARA hunting rule.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.