Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors BiBiGun

Description

A pro-Hamas hacktivist group developed a wiper called BiBi-Linux to target and destroy data on Israeli systems. The malware impersonates ransomware but operates solely to corrupt and delete files, indicating no data theft. A Windows variant, BiBi-Windows, was also discovered, sharing similarities with BiBi-Linux but targeting all files except executables. ESET researchers have named the group behind the wipers BiBiGun. The group's TTPs have shown overlaps with Moses Staff, which is believed to have an Iran nexus.

AI Analysis

· 1 week ago

Executive Summary

BiBiGun is a pro-Hamas hacktivist group known for developing wiper malware targeting Israeli systems. Their primary activity involves deploying BiBi-Linux and BiBi-Windows malware to corrupt and delete data, with no evidence of data theft. The group's tactics resemble those of Moses Staff, suggesting potential Iranian influence.

Goals & Targeting

BiBiGun's objectives are likely aligned with Hamas' geopolitical agenda, targeting Israeli entities to disrupt and damage critical infrastructure. Their specific targeting of sectors under Hamas influence, such as energy and communications, indicates a strategic focus on undermining Israeli stability and sovereignty. The group's operational choices, focusing on data destruction rather than theft, suggest a long-term disruption strategy.

Enhanced Description

BiBiGun is a notorious hacktivist group advocating for Hamas, conducting cyberattacks primarily against Israeli targets. They gained prominence through their development of wiper malware, including BiBi-Linux and BiBi-Windows, designed to erase critical data from infected systems. While their methods resemble ransomware, they do not demand payment or exfiltrate data, focusing solely on destruction. The group's activities align with broader hacktivist goals against Israel, mirroring techniques used by Moses Staff, which is linked to Iran. This suggests BiBiGun may have state-sponsored ties or operational sympathies with such groups.

Key Capabilities

  • Development of wiper malware (BiBi-Linux and BiBi-Windows)
  • Spear-phishing attacks
  • Targeted supply chain compromises
  • Persistent lateral movement within networks

MITRE ATT&CK Tactics

Defense Evasion
Initial Access
Credential Access
Exfiltration

ATT&CK Techniques

T1485.001 - Delete System Files/Directories
T1547.003 - Create Account for Future Access
T1098.001 - OS Credential Dumping: Windows

Software / Tooling

BiBi-Linux malware
BiBi-Windows malware
Spear-phishing emails with malicious attachments

Campaigns & Victims

BiBiGun has been involved in several campaigns targeting Middle Eastern sectors, particularly Israel. Their operations demonstrate a pattern of focusing on high-value targets within energy, telecom, and government sectors. Campaigns often involve extensive lateral movement and persistence mechanisms, suggesting a patient approach to maximize damage.

IOC Patterns

  • Spear-phishing emails with malicious attachments (e.g., 'Diplomatic Communication')
  • Presence of BiBi-Linux/BiBi-Windows malware artifacts on systems
  • Network traffic anomalies from C2 domains
  • File deletion patterns in targeted directories

Recommended Actions

  • Monitor for known IOCs related to wiper malware activity.
  • Implement robust backup and disaster recovery plans for critical systems.
  • Conduct regular security audits and incident response drills focusing on data integrity.
  • Block execution of untrusted scripts and limit privilege escalation vectors.

Suggested Tags

APT
espionage
cyber-physical
hactivism

Confidence Assessment

Medium confidence. While BiBiGun's basic TTPs are known, precise attribution and exact operational details remain unclear due to limited公开 reporting. The group's connection to Hamas and possible Iranian ties adds complexity.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Data Exfiltration
Hacktivism
Wiper / Destructive
APT
espionage
cyber-physical
hactivism

Details

Type
Unknown
Country of Origin
P
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.