BiBiGun is a pro-Hamas hacktivist group using wiper malware disguised as ransomware to destroy Israeli systems.
Analyst brief
BiBiGun is a pro-Hamas hacktivist group that targets Israeli systems with the BiBi-Linux and BiBi-Windows wipers, designed purely to corrupt and delete data while impersonating ransomware. Their TTPs show overlaps with the Iran-linked Moses Staff group. Defenders should focus on maintaining strictly isolated offline backups and monitor for anomalous file destruction behavior, as no data exfiltration is involved.
BiBiGun
unknown
A pro-Hamas hacktivist group developed a wiper called BiBi-Linux to target and destroy data on Israeli systems. The malware impersonates ransomware but operates solely to corrupt and delete files, indicating no data theft. A Windows variant, BiBi-Windows, was also discovered, sharing similarities with BiBi-Linux but targeting all files except executables. ESET researchers have named the group behind the wipers BiBiGun. The group's TTPs have shown overlaps with Moses Staff, which is believed to have an Iran nexus.
How does BiBiGun's use of BiBi-Linux and BiBi-Windows wipers differ from typical ransomware attacks?+
The BiBiGun group uses these wipers purely to corrupt and delete data, but they impersonate ransomware during the attack to distract from the actual goal of data destruction. No data exfiltration is involved.
Which other threat actor does BiBiGun's TTPs overlap with?+
BiBiGun's TTPs show overlaps with the Moses Staff group, which is believed to have an Iran nexus.