This wiper malware takes data destruction to a whole new level

The BiBi Wiper now deletes the disk partition table, making data recovery harder.

This wiper malware takes data destruction to a whole new level


Click the link to join the registration on WhatsApp: https://chat.whatsapp.com/KThkuZlWaTcCu3iJHGBmLM


Click the link to join the registration on WhatsApp: https://chat.whatsapp.com/KThkuZlWaTcCu3iJHGBmLM


Click the link to join the registration on WhatsApp: https://chat.whatsapp.com/KThkuZlWaTcCu3iJHGBmLM

Security researchers have observed a new version of BiBi Wiper, a destructive piece of malware that not only wipes all of the data from the disk, but now also deletes the disk partition table as well. As a result, data recovery takes far more time and effort. 

The malware is built for both Linux and Windows operating systems, with minor differences between them. Generally speaking, non-system files get corrupted with random data, and also get a randomly generated extension with the “BiBi” string.

As reported by BleepingComputer, the new variant was spotted by Check Point Research, whose experts also found two additional custom wipers called Cl Wiper and Partition Wiper. The malware allegedly belongs to Void Manticore, AKA Storm-842, an Iranian state-sponsored threat actor. Their targets include organizations in Israel, and Albania. 

Cooperating with Scarred Manticore

BiBi Wiper is reserved for Israeli victims, while CI Wiper focuses mostly on Albanian targets. Furthermore, BiBi Wiper does not delete shadow copies, or disable the system’s Error Recovery screen. Still, with partition information now also being removed, recovering the data is now significantly harder.

The researchers also claim that Void Manticore cooperates extensively with Scarred Manticore, a separate threat actor also on the payroll of Iran’s Ministry of Intelligence and Security.

Unlike Void Manticore, which usually deploys malware and exfiltrates sensitive data, Scarred Manticore is an initial access broker, whose only assignment is to find a way into their target’s IT infrastructure. Once that goal is achieved, the access is handed over to Void Manticore for further action.

To obtain that access, Scarred Manticore mostly abuses CVE-2019-0604, a vulnerability in Microsoft Sharepoint, to move laterally throughout the network, and steal emails. 

Among the different tools in Void Manticore’s arsenal is Karma Shell, a custom web shell that hides behind a fake error page. This web shell lists directories, creates processes, can upload files, and manage servers, BleepingComputer further stated. 

More from TechRadar Pro

What's Your Reaction?

like

dislike

love

funny

angry

sad

wow

Keep advertising to get more people

You could reach thousands of more people for every ₦1,000 you spend. https://doacweb.com/advertising

Adverts on doacWeb can be informative, educative or persuasive in nature.

doacWeb Ads is always directed at a broad audience (reaching thousands of people day by day), not few individuals — it deliver your advert to the target audience at the same time. Putting your offer in front of the right people — who have the money and interest in what you sell.

doacWeb Advertising gives you advantage as adverts passes through https://doacweb.com to the internet, reaching millions of people over the internet, and to grow your audience.

Grow your business, Be known, Boost your visibility, Drive engagements, Get new customers and Increase sales.

doacWeb acts as a global advertising media, to let people — individuals — and businesses, to promote and reach more interested people.

Get Started.

WhatsApp: 09031633831

Email: info@doacweb.com
Keep advertising to get more people

You could reach thousands of more people for every ₦1,000 you spend. https://doacweb.com/advertising

Adverts on doacWeb can be informative, educative or persuasive in nature.

doacWeb Ads is always directed at a broad audience (reaching thousands of people day by day), not few individuals — it deliver your advert to the target audience at the same time. Putting your offer in front of the right people — who have the money and interest in what you sell.

doacWeb Advertising gives you advantage as adverts passes through https://doacweb.com to the internet, reaching millions of people over the internet, and to grow your audience.

Grow your business, Be known, Boost your visibility, Drive engagements, Get new customers and Increase sales.

doacWeb acts as a global advertising media, to let people — individuals — and businesses, to promote and reach more interested people.

Get Started.

WhatsApp: 09031633831

Email: info@doacweb.com
Keep advertising to get more people

You could reach thousands of more people for every ₦1,000 you spend. https://doacweb.com/advertising

Adverts on doacWeb can be informative, educative or persuasive in nature.

doacWeb Ads is always directed at a broad audience (reaching thousands of people day by day), not few individuals — it deliver your advert to the target audience at the same time. Putting your offer in front of the right people — who have the money and interest in what you sell.

doacWeb Advertising gives you advantage as adverts passes through https://doacweb.com to the internet, reaching millions of people over the internet, and to grow your audience.

Grow your business, Be known, Boost your visibility, Drive engagements, Get new customers and Increase sales.

doacWeb acts as a global advertising media, to let people — individuals — and businesses, to promote and reach more interested people.

Get Started.

WhatsApp: 09031633831

Email: info@doacweb.com