Skip to main content
Mallory
MalwareUsed by 1 actor

Bibi wiper

BiBi Wiper is a destructive wiper malware family/variant used in campaigns attributed to the Iran-linked threat cluster tracked as VOID MANTICORE, Storm-0842, BANISHED KITTEN, and associated Handala/KarmaBelow personas, with reporting linking the activity to Iran’s Ministry of Intelligence and Security (MOIS). The malware is named in reference to Israeli Prime Minister Benjamin “Bibi” Netanyahu. Content states that KarmaBelow targeted the Israeli government with BiBi Wiper, and that in late October 2023 operators associated with Storm-0842 deployed the Bibi wiper at an Israeli organization. BiBi Wiper is described as part of a broader Handala/Void Manticore wiper toolkit that includes Hatef, Hamsa for Linux, CoolWipe, ChillWipe, Cl Wiper, and Handala Wiper. The reporting places it in destructive campaigns against Israeli targets and in broader operations spanning both Windows and Linux environments. VOID MANTICORE is described as using Group Policy logon scripts and batch files to distribute malicious payloads, phishing and exploitation for initial access, Telegram Bot API for command-and-control in related operations, and other destructive techniques including file deletion, data wiping, disk wiping, and inhibition of recovery. One mention specifically references historical detection opportunities based on BiBi Wiper file extension patterns. High-confidence targeting in the content centers on Israeli government and Israeli organizations.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Handala

KarmaBelow has targeted the Israeli government, deploying destructive malware called the “BiBi wiper” (named after Israeli Prime Minister Benjamin “Bibi” Netanyahu).

via recorded future blogrecordedfuture.com
MITRE ATT&CK

Techniques & procedures

6 distinct techniques documented for this family, organized by ATT&CK tactic.

T1587.001MalwareEvidence1

VOID MANTICORE has utilized custom-malware and wipers to include BiBi Wiper.

Initial Access

2 techniques
T1566.001Spearphishing AttachmentEvidence1

The most studied example is a phishing campaign from July 2024 that exploited the global CrowdStrike outage. The group sent emails to Israeli organizations with fake remediation tools. Victims who downloaded the archive got hit with a multi-stage chain that ended in a wiper payload erasing their files.

T1566.002Spearphishing LinkEvidence1

Victims were directed to download a malicious archive containing a disguised installer that deployed a destructive wiper payload.

Exfiltration

1 technique
T1567Exfiltration Over Web ServiceEvidence1

Between 2022 and 2025, Void Manticore personas frequently conducted hack-and-leak operations and wiper attacks, which it subsequently amplified by publicly leaking information from targeted organizations.

Impact

2 techniques
T1485Data DestructionEvidence4
TacticImpact

Between 2022 and 2025, Void Manticore personas frequently conducted hack-and-leak operations and wiper attacks... KarmaBelow has targeted the Israeli government, deploying destructive malware called the “BiBi wiper”.

T1561.002Disk Structure WipeEvidence2
TacticImpact

MITRE ATT&CK TTPs Tactic ID Technique Impact T1561.002 Disk Structure Wipe

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping6

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.