BiBi is a destructive wiper malware family associated with anti-Israeli and Iranian-aligned operations during the Israel-Hamas conflict period. It has been publicly linked to disruptive campaigns against Israeli targets and has been referenced alongside other regional wipers such as Hatef, Hamsa, No-Justice, and BABYWIPER. Reporting has also associated BiBi-related activity with actors including Handala and, in some accounts, Arid Viper, while broader analysis places it within the evolution of Iranian state-aligned disruptive tradecraft.
BiBi is notable for cross-platform destructive capability, with both Linux and Windows variants observed. The Linux variant has been described as Bash-based and aimed at Linux server environments, while Windows use has also been documented. BiBi has been used to support system disruption and paralysis of victim environments, including sectors such as healthcare, education, and infrastructure. In broader regional campaigns, it has been characterized as part of politically motivated destructive operations intended to damage systems and amplify messaging impact.
Behaviorally, BiBi is a wiper rather than a financially motivated payload. Available reporting indicates destructive file-overwrite activity and, in Windows operations, use of the Windows Restart Manager component to terminate processes that could interfere with execution, including security tooling. This aligns with its role in disabling defenses and maximizing destructive impact. Cross-references in intrusion reporting also place BiBi among wipers deployed after compromise of exposed services or through broader disruptive campaigns, but high-confidence, malware-specific initial delivery details remain limited.
BiBi has figured in a wider trend in Middle Eastern cyber operations toward overt sabotage, including destructive malware deployed either directly or in combination with legitimate administrative tooling and remote management abuse. Its emergence underscored a shift from single-platform wipers to coordinated cross-platform destructive tooling capable of affecting both Windows endpoints and Linux servers.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Handala combines information gathering and system disruption to paralyze healthcare, education, and infrastructure with BiBi/Hatef wiper and expand political influence with public messaging.
One wiper malware example was named BiBi for political reasons (to provoke the Israeli government and the man leading it, Benjamin “Bibi” Netanyahu.) The malware was discovered both for Linux and Windows systems, indicating sophisticated capabilities on the part of the originator.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
In two recent major geopolitical conflicts, in Ukraine and in Israel, wipers - malware used to destroy access to files and commonly used to halt telecom operations - were used to destroy digital infrastructure.
The RstrtMgr DLL (Restart Manager) is being loaded by an uncommon process. This library has been used during ransomware campaigns to kill processes that would prevent file encryption by locking them... It could also be used for anti-analysis purposes by shutting down specific processes.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a wiper targeting Israel after October 2023.
A wiper used for system disruption against organizations in healthcare, education, and infrastructure.
A Bash-based Linux wiper used in cross-platform destructive operations, focused on rapid file-level destruction.
A wiper referenced as having used Windows Restart Manager (RstrtMgr.dll) to terminate security processes, facilitating destructive activity by disabling defenses.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.