{"id":6960,"date":"2024-05-23T17:23:38","date_gmt":"2024-05-23T11:53:38","guid":{"rendered":"https:\/\/pczippo.com\/?p=6960"},"modified":"2024-05-23T17:24:18","modified_gmt":"2024-05-23T11:54:18","slug":"bibi-wiper-total-wipe-including-your-partition-table","status":"publish","type":"post","link":"https:\/\/pczippo.com\/tech\/bibi-wiper-total-wipe-including-your-partition-table\/","title":{"rendered":"BiBi Wiper: Total Wipe – Including Your Partition Table"},"content":{"rendered":"\n
\"\"<\/figure>\n\n\n\n

A new iteration of the BiBi Wiper malware now obliterates the disk partition table, complicating data recovery efforts and extending the downtime for its victims.<\/p>\n\n\n\n

BiBi Wiper attacks on Israel and Albania have been linked to a suspected Iranian hacking group known as ‘Void Manticore’ (Storm-842), believed to be associated with Iran’s Ministry of Intelligence and Security.<\/p>\n\n\n\n

Security Joes identified BiBi Wiper in October 2023, and its actions led to an alert from Israel’s CERT in November 2023 regarding extensive cyberattacks targeting crucial national infrastructure.<\/p>\n\n\n\n

Recent research from Check Point Research unveils updated versions of the BiBi Wiper, along with two additional custom wipers used by the same threat actor: Cl Wiper and Partition Wiper.<\/p>\n\n\n\n

The study also highlights operational similarities between Void Manticore and ‘Scarred Manticore,’ another Iranian threat group, suggesting a potential collaboration between the two.<\/p>\n\n\n\n

\"This<\/figure>\n\n\n\n
\n
\n

Table of Contents<\/p>\nToggle<\/span><\/path><\/svg><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n