ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Malware

Bibi-Linux Malware Unleashed on Israeli Linux Systems: A New Data-Wiping Threat

Kyle by Kyle
October 30, 2023
in Malware
Reading Time: 3 mins read
Bibi Linux malware strain data wiping
Share on FacebookShare on Twitter

The Security Joes Incident Response team has uncovered a malicious data-wiping threat known as “BiBi-Linux.” This malware has been employed in targeted attacks against Linux systems owned by Israeli companies.

You might also like

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

The discovery was made during an investigation into a network breach within an Israeli organization. Currently, only two malware scanning engines on VirusTotal identify BiBi-Linux as a threat. Unlike traditional ransomware, BiBi-Linux refrains from dropping ransom notes or providing communication channels for victims to negotiate decryption payments. However, it mimics file encryption.

Security Joes explained, “This new threat does not establish communication with remote Command & Control (C2) servers for data exfiltration, employ reversible encryption algorithms, or leave ransom notes as a means to coerce victims into making payments. Instead, it conducts file corruption by overwriting files with useless data, damaging both the data and the operating system.”

The malware, in the form of an x64 ELF executable named “bibi-linux.out,” grants attackers the ability to choose specific folders for encryption using command-line parameters. In the absence of a specified target path, if the payload runs with root privileges, it can entirely wipe the operating system by attempting to delete the root directory (‘/’).

bibi linux out
Hardcoded “BiBi” string within the malware sample. Credit: Security Joes

BiBi-Linux utilizes multiple threads and a queue system for enhanced speed and effectiveness, overwriting file contents and appending a ransom-like extension featuring the term ‘BiBi’ (a nickname for Israel’s Prime Minister, Benjamin Netanyahu) followed by a number, indicating the number of file wipes.

Notably, the malware sample lacks obfuscation, packing, or other protective measures, simplifying the work of malware analysts. This suggests that the threat actors prioritize maximizing the impact of their attacks over evading analysis.

The use of destructive malware is not exclusive to this case. Russian threat groups, particularly after the invasion of Ukraine in February 2022, have widely utilized data-wiping malware to target Ukrainian organizations. Some of the wiper malware employed in these attacks include DoubleZero, HermeticWiper, IsaacWiper, WhisperGate, and AcidRain.

Russian Sandworm military hackers deployed multiple data-wiping malware strains on the network of Ukraine’s national news agency, Ukrinform, in January, illustrating the growing concern over these destructive tools in cyberattacks.

Tags: BiBi-Linuxlinux
Previous Post

A Floridian Cybercriminal Sentenced to Prison for Million-Dollar Cryptocurrency Heist

Next Post

North Korean State-Backed Hackers Utilize Known Software Vulnerabilities

Kyle

Kyle

Writer, and editor at ZeroSecurity. Interested in Information Security, the Blockchain, and an overall tech enthusiast. "Formal education will make you a living; self-education will make you a fortune." Contact me here: [email protected]

Recommended For You

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

Chinese Hackers Hijack Notepad++ Updates in 6-Month Supply Chain Campaign

February 6, 2026
Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

January 1, 2025

BadBox Botnet Infects Over 190,000 Android Devices Worldwide

December 20, 2024

FBI Warns of HiatusRAT Targeting Network Devices Worldwide

December 18, 2024

Was Deloitte Hacked Again? Ransomware Group Claims They Did

December 9, 2024

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.