Pro-Hamas hacktivist activity targeting Israeli entities has expanded from disruptive website attacks to destructive malware, with researchers linking multiple campaigns to wiper operations designed to render systems unusable. Reports on BiBi Wiper said the malware was deployed in the context of the Israel-Hamas war and evolved from Linux-focused variants to a Windows version, broadening the range of systems at risk. The malware was described as overwriting files and damaging hosts rather than stealing data, underscoring an intent to disrupt operations and create visible impact.
Separate research on Handala described another wiper campaign aimed at Israeli targets, reinforcing a pattern of politically motivated destructive attacks against organizations in the country. Together, the reporting indicates that pro-Hamas-aligned actors are using wipers as a core tactic against Israeli networks, with malware families including BiBi Wiper and Handala adapted for different environments and used to sabotage systems, interrupt business activity, and amplify the conflict in cyberspace.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
Trellix released research describing a wiper used by the Handala group against Israeli targets, adding technical detail on a destructive malware campaign associated with anti-Israel operations. The reference indicates continued wiper-focused activity against Israel by a named threat actor.
Security reporting revealed that the BiBi wiper had expanded to a Windows variant, indicating the malware family was adapted beyond Linux systems for attacks on Israeli targets. The reporting tied the activity to the same broader pro-Hamas hacktivist campaign.
A Linux-based wiper dubbed BiBi-Linux was used in attacks against Israeli entities in the context of the Israel-Hamas war. Researchers linked the malware to pro-Hamas hacktivist activity targeting Israeli organizations.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
trellix.com
Open sourcearcticwolf.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.