Exfiltration
- File[.]io
Babuk is a ransomware family first identified in January 2021 following attacks against large enterprises.
Profile source: Mallory opens in a new tabBabuk
Babuk is a ransomware family first identified in January 2021 following attacks against large enterprises. The Babuk operation targeted organizations in manufacturing, transportation, construction and materials, and legal services, with reported victims concentrated in the United States, Canada, Spain, France, and Germany. Babuk encryptors were built for Windows, VMware ESXi, and NAS architectures, reflecting a focus on both endpoint and virtualized enterprise environments.
Babuk encrypts victim data in parallel using multiple processor-dependent threads and leaves ransom instructions for recovery. Its Windows implementation can enumerate running processes and network shares, terminate processes or services that could impede encryption, delete Volume Shadow Copies, stop VSS-related activity, and empty the Recycle Bin to obstruct restoration. Samples can unpack themselves in memory using XOR obfuscation and use Windows APIs for discovery and execution. A publicly leaked Babuk builder and source code enabled the creation of platform-specific encryptor and decryptor binaries and has subsequently been reused or adapted by multiple ransomware operations, particularly in ESXi-focused attacks.
Reported operators
Head Mare is a hacktivist group that targets Russian and Belarusian organizations; the group has been active since at least 2023 and has previously used LockBit and Babuk ransomware to encrypt victims’ systems, according to Kaspersky.
このRA Groupが使用しているランサムウェアは、2021年に流出した「Babuk」というランサムウェアのソースコードを元に作成されたと考えられています。
Indictments returned in New Jersey and the District of Columbia allege that Matveev was involved in a conspiracy to distribute ransomware from three different strains or affiliate groups, including Babuk, Hive and LockBit.
Babuk Ransomware v3 Overview This is a short report for the latest Babuk ransomware sample. This sample is marked as version 3 based on the run-once mutex string.
Для Linux используется шифровальщик на основе исходных кодов вымогателя Babuk.
Babuk, an advanced ransomware strain, was publicly discovered in 2021... Avast is releasing an updated version of the Avast Babuk decryption tool, capable of restoring files encrypted by the Babuk variant called Tortilla.
Ce groupe utilisait auparavant des ransomwares tiers (RedAlert, LockBit, Babuk).
...для шифрования файлов — LockBit 3 (Black) и Babuk...
...для шифрования файлов — LockBit 3 (Black) и Babuk...
Talos IR responded to Warlock, Babuk and Kraken ransomware variants for the first time... Notably, we also observed evidence of Babuk ransomware files on the customer’s network in this engagement, which has not been previously deployed by Storm-2603 according to public reporting, though it failed to encrypt and only renamed files.
As the final payload, the group used the well-known ransomware LockBit 3.0 and Babuk.
As the final payload, the group used the well-known ransomware LockBit 3.0 and Babuk.
SentinelLABS observed an increase in VMware ESXi ransomware based on Babuk ( aka Babak, Babyk). The Babuk leaks in September 2021 provided unprecedented insight into the development operations of an organized ransomware group.
Authorities say Matveev played a major role in the development and deployment of the Hive, LockBit and Babuk ransomware variants...
On Dec. 31, 2020, they announced the creation of the Babuk ransomware affiliate program... On January 1, 2021, a new user “Babuk” registered on the crime forum Verified... “We run an affiliate program,” Babuk explained in their introductory post on Verified.
On Dec. 31, 2020, they announced the creation of the Babuk ransomware affiliate program... On January 1, 2021, a new user “Babuk” registered on the crime forum Verified... “We run an affiliate program,” Babuk explained in their introductory post on Verified.
The hacking group was first documented by F6 in September 2025 as leveraging encryptors associated with LockBit 3 (Black) and Babuk.
Warlock has employed multiple different encryptors over time, ranging from custom ones to variants based on Babyk...
"...others support or sell ESXi encryptors like Akira, Black Basta, Babuk, Lockbit, and Kuiper."
"...others support or sell ESXi encryptors like Akira, Black Basta, Babuk, Lockbit, and Kuiper."
"...others support or sell ESXi encryptors like Akira, Black Basta, Babuk, Lockbit, and Kuiper."
...used open-source and leaked builders from other operators, including LockBit, Babuk and Conti.
"...others support or sell ESXi encryptors like Akira, Black Basta, Babuk, Lockbit, and Kuiper."
Lockers such as Babuk and LockBit.
...deploying multiple strains of ransomware based on the leaked Babuk source code.
Exploited software
MITRE ATT&CK
Reporting
A malicious installer posing as signed QN Wallpaper adware is deploying the ValleyRAT backdoor by DLL sideloading a trojanized libcef.dll through QnWallpaper.exe or QnwPlayer.exe. The malware disables Microsoft Defender, establishes persistence, decrypts and reflectively loads its payloads, and selects command-and-control configurations based on the host executable. ValleyRAT supports surveillance, host reconnaissance, anti-analysis, process protection, command execution, and delivery of additional modules. Kaspersky recorded more than 100,000 detections affecting over 1,500 unique users during 2026, primarily in China and India. The campaign abuses a signed legitimate application to evade security controls—a DLL-sideloading pattern used by both advanced persistent threat and ransomware actors—and its geography and ValleyRAT use indicate that Silver Fox is the likely operator.
AZORult, a long-running credential-stealing malware family tied to the Genesis Store cybercrime marketplace, has continued to appear in new delivery campaigns despite earlier reports that browser security changes had crippled its core theft capabilities. Earlier research linked more than 300,000 infections sold through Genesis to AZORult or its suppliers, showing how the malware fit into a broader malware-as-a-service and stolen-access supply chain. Although a Google Chrome update was reported to have disrupted older AZORult builds and pushed some criminal operators toward other stealers, subsequent activity indicates the malware remained in circulation through updated or repackaged campaigns. Recent and historical reporting shows AZORult being distributed through spam emails, ZIP or ISO archives, malicious LNK and HTA files, and heavily obfuscated script chains using PowerShell, batch files, JavaScript, and scheduled tasks. The malware has been used against targets including Korean users and German automotive businesses, where it stole browser credentials, cookies, autofill data, email and messaging app data, cryptocurrency wallet files, screenshots, and system information, while also supporting follow-on payload delivery. Newer campaigns emphasized in-memory execution, anti-analysis checks, and minimal disk artifacts to evade detection, underscoring AZORult's persistence as a commodity infostealer within a more outsourced and opportunistic cybercrime ecosystem.
Researchers reported that the financially motivated Toy Ghouls group has deployed a new custom ransomware family, GenieLocker, against organizations in the Russian Federation, with manufacturing firms highlighted among the victims. Active since March 2026, the malware marks a shift away from third-party ransomware such as RedAlert, LockBit, and Babuk to a cross-platform encryptor built for Windows, Linux, and VMware ESXi environments. In a documented intrusion, the attackers reportedly entered through an OpenVPN connection belonging to a trusted external partner by using stolen valid credentials, then expanded access with OpenSSH, SoftPerfect Network Scanner, Mimikatz, PsExec, and PAExec. The Windows variant uses anti-debugging protections, requires a secret launch argument, terminates processes and services, and encrypts data with libsodium implementations of XChaCha20-Poly1305 and Curve25519-XSalsa20-Poly1305, while the Linux/ESXi build includes ESXi-specific behavior such as modifying /etc/vmware/welcome and targeting /vmfs/volumes; researchers said the group typically focuses on encryption rather than data theft or leak-site extortion.
Krybit has emerged as a ransomware-as-a-service (RaaS) operation using double extortion, Tor-hosted leak infrastructure, and a likely Babuk-derived payload targeting Windows, Linux, VMware ESXi, and NAS environments. Reporting indicates the malware deletes shadow copies, appends the .KRYBIT extension to encrypted files, and drops a RECOVER-README.txt ransom note. The group has pursued broad, opportunistic victimization across 43 countries, with Germany, Spain, and Brazil among the most affected geographies and professional services, technology, and manufacturing among the most targeted sectors. Public visibility into Krybit increased after rival RaaS operator 0APT breached Krybit’s affiliate panel in April, exposing plaintext credentials, user roles, negotiation data, Tox IDs, and Bitcoin wallets, with leaked records showing about 20 victims in active negotiations and ransom demands ranging from $40,000 to $100,000. Krybit retaliated by compromising and defacing 0APT’s leak site and publishing its operational data, creating a notable ransomware-on-ransomware conflict. Despite the reputational damage and evidence that no confirmed ransom payment had yet been recorded during the leaked period, Krybit continued naming victims through mid-2026 and showed no public signs of shutting down or rebranding.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.