BiBi Wiper Used in the Israel-Hamas War Now Runs on Windows
ID: 414b5036-f960-58f9-b864-6f550a053360
STIX ID: report--414b5036-f960-58f9-b864-6f550a053360
Feed Name: Arctic Wolf Blog
Threat Score
Arctic Wolf Labs reports on a BiBi-Windows wiper, a x64 Visual Studio 2019-compiled PE linked to pro-Hamas hacktivists and a previously reported Linux variant; the malware overwrites most user files with random bytes, renames them with a .BiBi[number] extension, deletes shadow copies, disables Windows recovery mechanisms, uses RTL-obfuscated CMD strings to evade simple detections, leverages Restart Manager to ensure completion, and includes provided IOCs and a YARA hunting rule.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
