This wiper malware takes data destruction to a whole new level

microsoft, this wiper malware takes data destruction to a whole new level

Image Credit: Shutterstock

Security researchers have observed a new version of BiBi Wiper, a destructive piece of malware that not only wipes all of the data from the disk, but now also deletes the disk partition table as well. As a result, data recovery takes far more time and effort.

The malware is built for both Linux and Windows operating systems, with minor differences between them. Generally speaking, non-system files get corrupted with random data, and also get a randomly generated extension with the “BiBi” string.

As reported by BleepingComputer, the new variant was spotted by Check Point Research, whose experts also found two additional custom wipers called Cl Wiper and Partition Wiper. The malware allegedly belongs to Void Manticore, AKA Storm-842, an Iranian state-sponsored threat actor. Their targets include organizations in Israel, and Albania.

Cooperating with Scarred Manticore

BiBi Wiper is reserved for Israeli victims, while CI Wiper focuses mostly on Albanian targets. Furthermore, BiBi Wiper does not delete shadow copies, or disable the system’s Error Recovery screen. Still, with partition information now also being removed, recovering the data is now significantly harder.

The researchers also claim that Void Manticore cooperates extensively with Scarred Manticore, a separate threat actor also on the payroll of Iran’s Ministry of Intelligence and Security.

Unlike Void Manticore, which usually deploys malware and exfiltrates sensitive data, Scarred Manticore is an initial access broker, whose only assignment is to find a way into their target’s IT infrastructure. Once that goal is achieved, the access is handed over to Void Manticore for further action.

To obtain that access, Scarred Manticore mostly abuses CVE-2019-0604, a vulnerability in Microsoft Sharepoint, to move laterally throughout the network, and steal emails.

Among the different tools in Void Manticore’s arsenal is Karma Shell, a custom web shell that hides behind a fake error page. This web shell lists directories, creates processes, can upload files, and manage servers, BleepingComputer further stated.

More from TechRadar Pro

    OTHER NEWS

    11 minutes ago

    Sonos Ace review: Excellent headphones, disappointing for Sonos

    11 minutes ago

    Amazon removes Prime Video film after one Ofcom complaint

    14 minutes ago

    Government sets new date for Rwanda removals amid High Court challenge

    17 minutes ago

    Need a pharmacy? These states and neighborhoods have less access

    17 minutes ago

    Aryna Sabalenka joins fellow big guns in French Open quarter-finals

    17 minutes ago

    How to apply blusher to suit your face shape, according to a make-up artist

    17 minutes ago

    Messi scores 12th goal of season, MLS-leading Inter Miami comes back to tie St. Louis

    17 minutes ago

    The shortest-ever Nürburgring 24 Hours: here’s what happened at this year’s event

    17 minutes ago

    4 mouth-watering ways you can use leftover roti

    17 minutes ago

    Massive downpour causes havoc in the East London area, five women missing

    17 minutes ago

    2 cops won $1.2M in the lottery, but said they won't quit because they want to set an example for their kids

    17 minutes ago

    Factbox-D-Day anniversary: key facts on the Allied Normandy landings

    17 minutes ago

    Tories will 'clarify' Equality Act

    17 minutes ago

    I'm fit and healthy but have had a cough for more than a year, what's causing it? DR MARTIN SCURR replies

    20 minutes ago

    Whole, fresh cucumbers sold in 14 states recalled due to possible salmonella

    22 minutes ago

    Peter Dutton ‘not afraid’ to criticise ABC and universities over antisemitism rise

    22 minutes ago

    Esteban Ocon to leave Alpine F1 team at the end of the season

    22 minutes ago

    June Kicks Off With Concerning Market Signals Brewing Under the Surface

    22 minutes ago

    New trains boost capacity – and wi-fi – on one of the UK’s busiest rail routes

    22 minutes ago

    This Morning's Cat Deeley in tears over Ben Shephard's stopcock blunder

    22 minutes ago

    Ticketmaster owner Live Nation confirms hackers offered to sell customer data

    22 minutes ago

    Research team makes breakthrough in solar technology with shell-shaped cells: 'Will be found beneficial in various application areas'

    22 minutes ago

    Gen-Z don't care about music at festivals like Glastonbury anymore

    22 minutes ago

    Spotify raises prices of premium subscription plans

    22 minutes ago

    Eagle-eyed Britain's Got Talent fan spots intriguing Ant and Dec detail after announcing Sydnie Christmas as winner

    22 minutes ago

    Levi Wright's mom says her final goodbyes as 'biggest fear' is revealed in health update

    22 minutes ago

    The one big secret that 'girl in the cupboard' Natasha Ryan took to her grave - as teen who shocked the world when she suddenly appeared after five YEARS missing is found dead at a golf course decades later

    22 minutes ago

    Video: How Rob Burrow's wife Lindsey became his carer and before his death rugby star said 'no-one is as strong as her'

    22 minutes ago

    Video: Claudia Sheinbaum becomes Mexico's first woman president with landslide victory in nation plagued by gang and gender-based violence

    22 minutes ago

    Video: Antiques Roadshow leaves viewers in tears after paying tribute to the Normandy landings with 'deeply humbling, moving and astonishing' D-Day special - while Fiona Bruce impresses viewers by speaking fluent French

    25 minutes ago

    Google’s latest data centre raises its investment in Singapore to $6.76 billion

    25 minutes ago

    Second seed Sabalenka bludgeons Navarro for French Open quarter-final spot

    26 minutes ago

    What's Bills 'Underappreciated' Status for Christian Benford Mean for Kaiir Elam?

    26 minutes ago

    Twist in Hawthorn racism saga, settlement denied

    26 minutes ago

    Front-runner emerges for vacant Eels coaching role

    26 minutes ago

    Next government urged to hold talks on nurses’ pay

    26 minutes ago

    GameStop soars as 'Roaring Kitty' reveals $116 million bet in Reddit post

    26 minutes ago

    Charles Barkley recalls when Tom Brady gave him his watch worth $250k: "I wouldn't sell it for any amount"

    26 minutes ago

    Pharma giant GSK plunges 9% after U.S. court allows scientific testimony in Zantac lawsuits

    26 minutes ago

    Stocks making the biggest moves premarket: GameStop, Stericycle, MarineMax, Paramount and more