Bibi wiper
BiBi Wiper is a destructive wiper malware family/variant used in campaigns attributed to the Iran-linked threat cluster tracked as VOID MANTICORE, Storm-0842, BANISHED KITTEN, and associated Handala/KarmaBelow personas, with reporting linking the activity to Iran’s Ministry of Intelligence and Security (MOIS). The malware is named in reference to Israeli Prime Minister Benjamin “Bibi” Netanyahu. Content states that KarmaBelow targeted the Israeli government with BiBi Wiper, and that in late October 2023 operators associated with Storm-0842 deployed the Bibi wiper at an Israeli organization. BiBi Wiper is described as part of a broader Handala/Void Manticore wiper toolkit that includes Hatef, Hamsa for Linux, CoolWipe, ChillWipe, Cl Wiper, and Handala Wiper. The reporting places it in destructive campaigns against Israeli targets and in broader operations spanning both Windows and Linux environments. VOID MANTICORE is described as using Group Policy logon scripts and batch files to distribute malicious payloads, phishing and exploitation for initial access, Telegram Bot API for command-and-control in related operations, and other destructive techniques including file deletion, data wiping, disk wiping, and inhibition of recovery. One mention specifically references historical detection opportunities based on BiBi Wiper file extension patterns. High-confidence targeting in the content centers on Israeli government and Israeli organizations.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
KarmaBelow has targeted the Israeli government, deploying destructive malware called the “BiBi wiper” (named after Israeli Prime Minister Benjamin “Bibi” Netanyahu).
Techniques & procedures
6 distinct techniques documented for this family, organized by ATT&CK tactic.
Resource Development
1 techniqueVOID MANTICORE has utilized custom-malware and wipers to include BiBi Wiper.
Initial Access
2 techniquesThe most studied example is a phishing campaign from July 2024 that exploited the global CrowdStrike outage. The group sent emails to Israeli organizations with fake remediation tools. Victims who downloaded the archive got hit with a multi-stage chain that ended in a wiper payload erasing their files.
Victims were directed to download a malicious archive containing a disguised installer that deployed a destructive wiper payload.
Exfiltration
1 techniqueBetween 2022 and 2025, Void Manticore personas frequently conducted hack-and-leak operations and wiper attacks, which it subsequently amplified by publicly leaking information from targeted organizations.
Impact
2 techniquesBetween 2022 and 2025, Void Manticore personas frequently conducted hack-and-leak operations and wiper attacks... KarmaBelow has targeted the Israeli government, deploying destructive malware called the “BiBi wiper”.
MITRE ATT&CK TTPs Tactic ID Technique Impact T1561.002 Disk Structure Wipe
Recent activity
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Destructive malware used against Israeli government targets; characterized in the content as a wiper intended to damage systems rather than for financial gain.
A wiper malware variant used by Handala for destructive attacks that erase or destroy victim data.
A wiper malware referenced as part of Handala’s historical toolkit, associated with destructive operations and detectable via file extension patterns.
Custom wiper malware used for destructive actions, including data destruction and disk wiping.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.