A Hamas-backed hacking group has been spotted using a new Linux-based wiper malware, dubbed BiBi-Linux Wiper, which is targeting Israeli entities during the ongoing Israel-Hamas war.
A hacking group has emerged in recent days, during the Middle East conflict between Israel and the Palestinian terrorist organization Hamas. The hacking group was recorded using Wiper Malware, a type of Malware capable of stealing data and application components of computers based on the Linux operating system.
See also: Cyberattacks increase as hackers threaten Israel's security

An extremely dangerous malware for operating systems, Wiper Malware can completely destroy them if given the right and finds an opening in security measures.
Israeli entities targeted by BiBi Linux Wiper.
While the name "BiBi" used in the Wiper Malware code as a string may sound random to you, it has significant relevance to the topic and has been associated many times with issues and policies concerning the Middle East.
Additionally, the nickname Bibi is often used for the Prime Minister of the Israeli government, Benjamin Netanyahu.
See also: Iranian Tortoiseshell group launches new waves of IMAPLoader Malware attacks
Being an x64 ELF executable, Wiper Malware allows hackers to easily target files and folders of their choice. Using the latest technology in tools and techniques, taking advantage of multithreading, it manages to increase its speed by destroying and replacing files with new ones of its own and then renaming them. Which will clearly contain the hard-coded string “BiBi” (in the form “[RANDOM_NAME].BiBi[NUMBER]”).

The Wiper Malware, coded in the C and C++ languages and with a file size of 1.2MB, frees the hands of hackers and distinguishes its targets through command-line parameters.
Of course, if no specific Path is given, then by default it targets the Root Directory ("/"). However, performing the action at this level requires root privileges.
When executing the "Nohup Command", BiBi-Linux Wiper runs quietly in the background. Some file types that are automatically skipped from being replaced are those with the .out or .so extensions, because without these files (bibi-linux.out, nohup.out) the Malware structure would collapse and the group shipment would fail.
See also: Avast flagged Google app as malware on Huawei smartphones
Arid Viper: Experts in the use of Wiper Malware and more
During the study of Hamas-influenced hacker groups, another malicious actor threatening Israeli entities emerged, named Arid Viper.
Generally, also known by its other names (APT-C-23, Desert Falcon, Gaza Cyber Gang or Molerats), Arid Viper is divided into two groups, focused on government espionage activities and consequently cyberattacks against Israel and Palestine respectively.
More specifically, hackers are targeting high-profile and large-scale groups, from sectors critical to governments, such as government organizations, national defense, police and law enforcement authorities, as well as parliamentary parties and political movements.
Therefore, Arid Viper's attacks on common users and individual systems are routine exercises.

The Arid Viper hackers’ “chained” orchestrated attacks may also involve Phishing and/or Social Engineering tactics. They exhaust every method and tactic and therefore launch a wide variety of Wiper Malware-laden attacks on their victims. Some examples include Mircopsia, PyMicropsia, Arid Gopher, BarbWire, and the undocumented Rusty Viper, coded in Rust.
Collectively, Arid Viper's arsenal includes a variety of espionage capabilities and capabilities. To name a few, it can record audio-visual content, detect imported flash drives, and then extract their contents, stealing various useful information such as browser credentials.
Source: thehackernews.com
