BiBi-Linux is a destructive Linux wiper used against Israeli organizations. Reporting cited in the content states it emerged as a cyber weapon during the October 2023 Gaza conflict and was observed being used by a pro-Hamas hacktivist group to target entities in Israel, with sabotage and data destruction as the motive. ESET named the actor behind the BiBi wipers as BiBiGun, with possible links to the Iran-nexus group Moses Staff. BiBi-Linux is described as an x64 ELF executable and as bibi-linux.out. Although it imitates ransomware behavior by faking file encryption, it is not ransomware: it irreversibly corrupts files, does not drop a ransom note, does not exfiltrate files, does not use reversible encryption algorithms, and does not communicate with a remote C2, indicating no data exfiltration. A Windows counterpart, BiBi-Windows, was also reported in the same campaign.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
BiBi-Linux is a wiper malware targeting Linux systems, designed for sabotage and data destruction. It corrupts files by overwriting them with useless data, can wipe an OS if run with root permissions, and uses multithreading for speed. It does not exfiltrate data or communicate with a C2 server.
Destructive Linux wiper that irreversibly corrupts files by overwriting data (not encryption), can wipe specified directories or entire root when run as root; no C2 and no ransom note.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.