Menu

  • Alerts
  • Incidents
  • News
  • APTs
  • Cyber Decoded
  • Cyber Hygiene
  • Cyber Review
  • Cyber Tips
  • Definitions
  • Malware
  • Threat Actors
  • Tutorials

Useful Tools

  • Password generator
  • Report an incident
  • Report to authorities
No Result
View All Result
CTF Hack Havoc
CyberMaterial
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
Hall of Hacks
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
No Result
View All Result
Hall of Hacks
CyberMaterial
No Result
View All Result
Home Alerts

BiBi-Windows Threat Expands

November 13, 2023
Reading Time: 6 mins read
in Alerts
BiBi-Windows Threat Expands

Cybersecurity researchers have identified a Windows version of the BiBi Wiper malware, originally used in cyber attacks targeting Israel. Dubbed BiBi-Windows Wiper by BlackBerry, this new variant signifies an escalation in the threat landscape, indicating that threat actors behind the wiper are expanding their operations to target end-user machines and application servers.

The Windows variant, tracked by Slovak cybersecurity firm as BiBiGun, operates by overwriting data in the C:\Users directory with junk data, adding .BiBi to filenames, and deleting shadow copies, making file recovery challenging for victims. The malware’s multithreading capabilities suggest a sophisticated and potentially more damaging approach in disrupting day-to-day operations. This BiBi-Windows Wiper is seen as part of a broader campaign, particularly targeting Israeli companies, with a deliberate intent to disrupt daily operations through data destruction.

Security Joes, the firm that first documented the BiBi-Linux Wiper, has identified tactical overlaps between the pro-Hamas hacktivist group, known as Karma, and another geopolitically motivated actor named Moses Staff, suspected to have Iranian origins. The campaign has historically focused on Israeli IT and government sectors, but some participating groups, like Moses Staff, have a track record of simultaneously targeting organizations across various business sectors and geographical locations. This highlights a coordinated and strategic effort to disrupt critical infrastructure. The BiBi-Windows Wiper was compiled on October 21, 2023, indicating its development in the aftermath of the Israel-Hamas war. The malware’s distribution method remains unknown, adding an element of unpredictability to its potential impact.

While it’s not immediately clear if the wiper has been deployed in real-world attacks or who the specific targets are, its existence underscores the evolving and adaptive nature of cyber threats, especially those originating from hacktivist groups engaged in geopolitical conflicts. The identification of this Windows variant further emphasizes the need for enhanced cybersecurity measures to safeguard against increasingly sophisticated and destructive cyber attacks.

Reference:

  • BiBi Wiper Used in the Israel-Hamas War Now Runs on Windows
Tags: BiBiGunCyber AlertCyber Alerts 2023Cyber AttacksCybersecurityIsraelMalwareNovember 2023WindowsWyper
ADVERTISEMENT

Related Posts

Fake PyPI Login Site Steals Credentials

Fake PyPI Login Site Steals Credentials

September 26, 2025
Fake PyPI Login Site Steals Credentials

Google Warns of BRICKSTORM Malware

September 26, 2025
Fake PyPI Login Site Steals Credentials

Hidden WordPress Backdoors Create Admins

September 26, 2025
BadIIS Malware Spreads Via SEO Poisoning

Hackers Target AWS and Steal Credentials

September 24, 2025
BadIIS Malware Spreads Via SEO Poisoning

SonicWall SMA100 Update Removes Rootkit

September 24, 2025
BadIIS Malware Spreads Via SEO Poisoning

BadIIS Malware Spreads Via SEO Poisoning

September 24, 2025

Latest Alerts

Fake PyPI Login Site Steals Credentials

Google Warns of BRICKSTORM Malware

Hidden WordPress Backdoors Create Admins

Hackers Target AWS and Steal Credentials

SonicWall SMA100 Update Removes Rootkit

BadIIS Malware Spreads Via SEO Poisoning

Subscribe to our newsletter

    Latest Incidents

    Indian Bank Transfer Records Exposed

    Chinese Cyberspies Hit US Defense Firms

    Neon App Shuts Down After Data Leak

    Boyd Gaming Reports Data Breach After Attack

    Morrisroe UK Company Hit By Cyber Attack

    GeoServer Flaw Breaches US Agency Network

    CyberMaterial Logo
    • About Us
    • Contact Us
    • Jobs
    • Legal and Privacy Policy
    • Site Map

    © 2025 | CyberMaterial | All rights reserved

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In

    Add New Playlist

    No Result
    View All Result
    • Alerts
    • Incidents
    • News
    • Cyber Decoded
    • Cyber Hygiene
    • Cyber Review
    • Definitions
    • Malware
    • Cyber Tips
    • Tutorials
    • Advanced Persistent Threats
    • Threat Actors
    • Report an incident
    • Password Generator
    • About Us
    • Contact Us
    • Advertise with us

    Copyright © 2025 CyberMaterial