BiBiGun is a threat actor name used for the cluster behind the BiBi-Linux and BiBi-Windows wiper campaigns that emerged during the Gaza conflict in late 2023. The activity is associated with destructive operations against Israeli targets and is characterized by sabotage and data destruction rather than conventional espionage or financially motivated crime. The group has been discussed as a pro-Hamas or anti-Israel actor, and some researchers have noted tactical overlaps with Moses Staff, although a definitive attribution to that group is not established. BiBiGun is known for deploying wiper malware on both Linux and Windows systems. Its operations indicate capabilities consistent with initial access, post-compromise destructive action, and data exfiltration or theft associated with intrusion activity. The actor’s tradecraft aligns with disruptive and destructive intrusion sets active in the Israel-Hamas conflict period, where website disruption, data breaches, and destructive malware were prominent. The most distinctive aspect of BiBiGun’s activity is the use of cross-platform wiper tooling intended to impair victim systems and destroy data at scale. No high-confidence evidence in the available facts supports ransomware operations, extortion activity, or a confirmed nation-state designation. The strongest supported characterization is a politically aligned destructive actor focused on Israeli entities.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.