The Israel National Cyber Directorate warns of phishing emails pretending to be F5 BIG-IP zero-day security updates that deploy Windows and Linux data wipers. Israel's National Cyber Directorate (INCD) acts as the CERT responsible for protecting the country from cyber threats and to warn organizations and citizens about known attacks. Since October, Israel has been heavily targeted by pro-Palestinian and Iranian hacktivists, who have been conducting data theft and data-wiping attacks on organizations in the country. In November, a new data wiper called BiBi Wiper was discovered that targeted both Linux and Windows devices and is believed to have been created by pro-Hamas hacktivists. Yesterday, INCD warned of a new phishing attack deploying data wipers through emails pretending to be a warning about a zero-day vulnerability in F5 BIG-IP devices. A pro-Palestinian hacktivist group named Handala told BleepingComputer that they were responsible for the phishing attack, stating it was deployed on numerous Israeli networks. BleepingComputer has not been able to confirm these claims independently. The phishing email warns that the F5 BIG-IP zero-day vulnerability is actively exploited in attacks, urging Israeli organizations to download and install a security update before their network is breached. For Windows users, the email pushes an executable named F5UPDATER.exe [VirusTotal], and for Linux, the file is a shell script named update.sh [VirusTotal]. When launched, both the Wind...
Fake F5 BIG-IP zero-day warning emails push data wipers
BleepingComputer
·Lawrence Abrams
·Published Dec 20, 2023
·Updated
Affected Software
1 affected component
F5 BIG-IP