This wiper malware takes data destruction to a whole new level

Malware Magnifying Glass
Image Credit: Shutterstock (Image credit: Andriano.cz / Shutterstock)

Security researchers have observed a new version of BiBi Wiper, a destructive piece of malware that not only wipes all of the data from the disk, but now also deletes the disk partition table as well. As a result, data recovery takes far more time and effort. 

The malware is built for both Linux and Windows operating systems, with minor differences between them. Generally speaking, non-system files get corrupted with random data, and also get a randomly generated extension with the “BiBi” string.

The new variant was spotted by Check Point Research, whose experts also found two additional custom wipers called Cl Wiper and Partition Wiper. The malware allegedly belongs to Void Manticore, AKA Storm-842, an Iranian state-sponsored threat actor. Their targets include organizations in Israel, and Albania. 

Cooperating with Scarred Manticore

BiBi Wiper is reserved for Israeli victims, while CI Wiper focuses mostly on Albanian targets. Furthermore, BiBi Wiper does not delete shadow copies, or disable the system’s Error Recovery screen. Still, with partition information now also being removed, recovering the data is now significantly harder.

The researchers also claim that Void Manticore cooperates extensively with Scarred Manticore, a separate threat actor also on the payroll of Iran’s Ministry of Intelligence and Security.

Unlike Void Manticore, which usually deploys malware and exfiltrates sensitive data, Scarred Manticore is an initial access broker, whose only assignment is to find a way into their target’s IT infrastructure. Once that goal is achieved, the access is handed over to Void Manticore for further action.

To obtain that access, Scarred Manticore mostly abuses CVE-2019-0604, a vulnerability in Microsoft Sharepoint, to move laterally throughout the network, and steal emails. 

Among the different tools in Void Manticore’s arsenal is Karma Shell, a custom web shell that hides behind a fake error page. This web shell lists directories, creates processes, can upload files, and manage servers.

Via BleepingComputer 

More from TechRadar Pro

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Industrial routers are being hit by zero-days from new Mirai botnets
Illustration of a laptop with a magnifying glass exposing a beetle on-screen
This devious macOS malware is evading capture by using Apple's own encryption
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Interlock ransomware attacks highlight need for greater security standards on critical infrastructure
Representational image of a cybercriminal
Microsoft discovers five potentially damaging attacks against its own software
Close up of the Linux penguin.
A new Linux backdoor is hitting US universities and governments
A digital representation of a lock
Security experts are being targeted with fake malware discoveries
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras
Security padlock and circuit board to protect data
Trust in digital services around the world sees a massive drop as security worries continue
A Lego Pikachu tail next to a Pebble OS watch and a screenshot of Assassin's Creed Shadow
ICYMI: the week's 7 biggest tech stories from LG's excellent new OLED TV to our Assassin's Creed Shadow review
Samuel and Romy standing very close together in A24's Babygirl movie
Everything new on Max in April 2025, including A24's Babygirl and The Last of Us season 2
An AMD Radeon RX 9070 XT made by Sapphire on a table with its retail packaging
AMD’s secret weapon against Nvidia seems to be stock – way more RX 9070 GPUs are rumored to be hitting shelves than RTX 5000 models