A pro-Hamas hacktivist group developed a wiper called BiBi-Linux to target and destroy data on Israeli systems. The malware impersonates ransomware but operates solely to corrupt and delete files, indicating no data theft. A Windows variant, BiBi-Windows, was also discovered, sharing similarities with BiBi-Linux but targeting all files except executables. ESET researchers have named the group behind the wipers BiBiGun. The group's TTPs have shown overlaps with Moses Staff, which is believed to have an Iran nexus.
Executive Summary
BiBiGun is a pro-Hamas hacktivist group known for developing wiper malware targeting Israeli systems. Their primary activity involves deploying BiBi-Linux and BiBi-Windows malware to corrupt and delete data, with no evidence of data theft. The group's tactics resemble those of Moses Staff, suggesting potential Iranian influence.
Goals & Targeting
BiBiGun's objectives are likely aligned with Hamas' geopolitical agenda, targeting Israeli entities to disrupt and damage critical infrastructure. Their specific targeting of sectors under Hamas influence, such as energy and communications, indicates a strategic focus on undermining Israeli stability and sovereignty. The group's operational choices, focusing on data destruction rather than theft, suggest a long-term disruption strategy.
Enhanced Description
BiBiGun is a notorious hacktivist group advocating for Hamas, conducting cyberattacks primarily against Israeli targets. They gained prominence through their development of wiper malware, including BiBi-Linux and BiBi-Windows, designed to erase critical data from infected systems. While their methods resemble ransomware, they do not demand payment or exfiltrate data, focusing solely on destruction. The group's activities align with broader hacktivist goals against Israel, mirroring techniques used by Moses Staff, which is linked to Iran. This suggests BiBiGun may have state-sponsored ties or operational sympathies with such groups.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
BiBiGun has been involved in several campaigns targeting Middle Eastern sectors, particularly Israel. Their operations demonstrate a pattern of focusing on high-value targets within energy, telecom, and government sectors. Campaigns often involve extensive lateral movement and persistence mechanisms, suggesting a patient approach to maximize damage.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Medium confidence. While BiBiGun's basic TTPs are known, precise attribution and exact operational details remain unclear due to limited公开 reporting. The group's connection to Hamas and possible Iranian ties adds complexity.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics