Skip to content

Malware

BiBi-Linux

According to Security Joes, this malware is an x64 ELF executable, lacking obfuscation or protective measures.

BiBi-Linux is a Linux malware family operated by Void Manticore.

Background

Security Joes reports that the malware is an x64 ELF binary with no obfuscation or protective measures. Operators can point it at specific folders, and when run with root privileges it is capable of wrecking an entire operating system. It generates a large volume of output during a run, which can be suppressed with the "nohup" command, and it spreads file corruption across multiple threads fed by a queue to work faster and reach more data. Its routine overwrites files and renames them with a random string containing "BiBi," while leaving certain file types untouched.


Source: Malpedia (Fraunhofer FKIE).