Skip to content

Babuk

Babuk is a ransomware family first identified in January 2021 following attacks against large enterprises.

Profile source: Mallory opens in a new tab

Babuk

Family profile

Babuk is a ransomware family first identified in January 2021 following attacks against large enterprises. The Babuk operation targeted organizations in manufacturing, transportation, construction and materials, and legal services, with reported victims concentrated in the United States, Canada, Spain, France, and Germany. Babuk encryptors were built for Windows, VMware ESXi, and NAS architectures, reflecting a focus on both endpoint and virtualized enterprise environments.

Babuk encrypts victim data in parallel using multiple processor-dependent threads and leaves ransom instructions for recovery. Its Windows implementation can enumerate running processes and network shares, terminate processes or services that could impede encryption, delete Volume Shadow Copies, stop VSS-related activity, and empty the Recycle Bin to obstruct restoration. Samples can unpack themselves in memory using XOR obfuscation and use Windows APIs for discovery and execution. A publicly leaked Babuk builder and source code enabled the creation of platform-specific encryptor and decryptor binaries and has subsequently been reused or adapted by multiple ransomware operations, particularly in ESXi-focused attacks.

Capabilities

  • Defense Evasion
  • Extortion
  • Reconnaissance

Operational record

1
YARA rules
2
Negotiations
1
Leak sites
0 available

Exfiltration

  • File[.]io

Reported operators

Threat actors

25 named in public reporting
Head Mare

Head Mare is a hacktivist group that targets Russian and Belarusian organizations; the group has been active since at least 2023 and has previously used LockBit and Babuk ransomware to encrypt victims’ systems, according to Kaspersky.

RA Group

このRA Groupが使用しているランサムウェアは、2021年に流出した「Babuk」というランサムウェアのソースコードを元に作成されたと考えられています。

Wazawaka

Indictments returned in New Jersey and the District of Columbia allege that Matveev was involved in a conspiracy to distribute ransomware from three different strains or affiliate groups, including Babuk, Hive and LockBit.

Babuk

Babuk Ransomware v3 Overview This is a short report for the latest Babuk ransomware sample. This sample is marked as version 3 based on the run-once mutex string.

Shadow

Для Linux используется шифровальщик на основе исходных кодов вымогателя Babuk.

Tortilla

Babuk, an advanced ransomware strain, was publicly discovered in 2021... Avast is releasing an updated version of the Avast Babuk decryption tool, capable of restoring files encrypted by the Babuk variant called Tortilla.

Toy Ghouls

Ce groupe utilisait auparavant des ransomwares tiers (RedAlert, LockBit, Babuk).

DARKSTAR

...для шифрования файлов — LockBit 3 (Black) и Babuk...

COMET

...для шифрования файлов — LockBit 3 (Black) и Babuk...

Storm-2603

Talos IR responded to Warlock, Babuk and Kraken ransomware variants for the first time... Notably, we also observed evidence of Babuk ransomware files on the customer’s network in this engagement, which has not been previously deployed by Storm-2603 according to public reporting, though it failed to encrypt and only renamed files.

Crypt Ghouls

As the final payload, the group used the well-known ransomware LockBit 3.0 and Babuk.

MorLock

As the final payload, the group used the well-known ransomware LockBit 3.0 and Babuk.

RansomHouse

SentinelLABS observed an increase in VMware ESXi ransomware based on Babuk ( aka Babak, Babyk). The Babuk leaks in September 2021 provided unprecedented insight into the development operations of an organized ransomware group.

Conti

Authorities say Matveev played a major role in the development and deployment of the Hive, LockBit and Babuk ransomware variants...

Boriselcin

On Dec. 31, 2020, they announced the creation of the Babuk ransomware affiliate program... On January 1, 2021, a new user “Babuk” registered on the crime forum Verified... “We run an affiliate program,” Babuk explained in their introductory post on Verified.

Orange

On Dec. 31, 2020, they announced the creation of the Babuk ransomware affiliate program... On January 1, 2021, a new user “Babuk” registered on the crime forum Verified... “We run an affiliate program,” Babuk explained in their introductory post on Verified.

Bearlyfy

The hacking group was first documented by F6 in September 2025 as leveraging encryptors associated with LockBit 3 (Black) and Babuk.

Warlock

Warlock has employed multiple different encryptors over time, ranging from custom ones to variants based on Babyk...

Storm-1175

"...others support or sell ESXi encryptors like Akira, Black Basta, Babuk, Lockbit, and Kuiper."

Storm-0506

"...others support or sell ESXi encryptors like Akira, Black Basta, Babuk, Lockbit, and Kuiper."

Scattered Spider

"...others support or sell ESXi encryptors like Akira, Black Basta, Babuk, Lockbit, and Kuiper."

Bl00Dy

...used open-source and leaked builders from other operators, including LockBit, Babuk and Conti.

INDRIK SPIDER

"...others support or sell ESXi encryptors like Akira, Black Basta, Babuk, Lockbit, and Kuiper."

ExCobalt

Lockers such as Babuk and LockBit.

Cinnamon Tempest

...deploying multiple strains of ransomware based on the leaked Babuk source code.

Exploited software

Vulnerabilities linked to Babuk

10 CVEs

MITRE ATT&CK

Babuk in ATT&CK

44 distinct techniques

Reporting

Research mentioning Babuk

Aug 31
Malware News

ValleyRAT masquerading as adware - Malware News - Malware Analysis, News and Indicators

A malicious installer posing as signed QN Wallpaper adware is deploying the ValleyRAT backdoor by DLL sideloading a trojanized libcef.dll through QnWallpaper.exe or QnwPlayer.exe. The malware disables Microsoft Defender, establishes persistence, decrypts and reflectively loads its payloads, and selects command-and-control configurations based on the host executable. ValleyRAT supports surveillance, host reconnaissance, anti-analysis, process protection, command execution, and delivery of additional modules. Kaspersky recorded more than 100,000 detections affecting over 1,500 unique users during 2026, primarily in China and India. The campaign abuses a signed legitimate application to evade security controls—a DLL-sideloading pattern used by both advanced persistent threat and ransomware actors—and its geography and ValleyRAT use indicate that Silver Fox is the likely operator.

Aug 31
Securelist

ValleyRAT is spreading disguised as adware | Securelist

Aug 12
Cylance Threatvector

Blog | Arctic Wolf

AZORult, a long-running credential-stealing malware family tied to the Genesis Store cybercrime marketplace, has continued to appear in new delivery campaigns despite earlier reports that browser security changes had crippled its core theft capabilities. Earlier research linked more than 300,000 infections sold through Genesis to AZORult or its suppliers, showing how the malware fit into a broader malware-as-a-service and stolen-access supply chain. Although a Google Chrome update was reported to have disrupted older AZORult builds and pushed some criminal operators toward other stealers, subsequent activity indicates the malware remained in circulation through updated or repackaged campaigns. Recent and historical reporting shows AZORult being distributed through spam emails, ZIP or ISO archives, malicious LNK and HTA files, and heavily obfuscated script chains using PowerShell, batch files, JavaScript, and scheduled tasks. The malware has been used against targets including Korean users and German automotive businesses, where it stole browser credentials, cookies, autofill data, email and messaging app data, cryptocurrency wallet files, screenshots, and system information, while also supporting follow-on payload delivery. Newer campaigns emphasized in-memory execution, anti-analysis checks, and minimal disk artifacts to evade detection, underscoring AZORult's persistence as a commodity infostealer within a more outsourced and opportunistic cybercrime ecosystem.

Jul 30
Malware News

Toy Ghouls’ new toy: the GenieLocker ransomware - Malware News - Malware Analysis, News and Indicators

Researchers reported that the financially motivated Toy Ghouls group has deployed a new custom ransomware family, GenieLocker, against organizations in the Russian Federation, with manufacturing firms highlighted among the victims. Active since March 2026, the malware marks a shift away from third-party ransomware such as RedAlert, LockBit, and Babuk to a cross-platform encryptor built for Windows, Linux, and VMware ESXi environments. In a documented intrusion, the attackers reportedly entered through an OpenVPN connection belonging to a trusted external partner by using stolen valid credentials, then expanded access with OpenSSH, SoftPerfect Network Scanner, Mimikatz, PsExec, and PAExec. The Windows variant uses anti-debugging protections, requires a secret launch argument, terminates processes and services, and encrypts data with libsodium implementations of XChaCha20-Poly1305 and Curve25519-XSalsa20-Poly1305, while the Linux/ESXi build includes ESXi-specific behavior such as modifying /etc/vmware/welcome and targeting /vmfs/volumes; researchers said the group typically focuses on encryption rather than data theft or leak-site extortion.

Jul 30
Securelist

New GenieLocker ransomware for Windows, ESXi, and Linux | Securelist

Jul 13
Malware News

Dark Web Profile: Krybit Ransomware - Malware News - Malware Analysis, News and Indicators

Krybit has emerged as a ransomware-as-a-service (RaaS) operation using double extortion, Tor-hosted leak infrastructure, and a likely Babuk-derived payload targeting Windows, Linux, VMware ESXi, and NAS environments. Reporting indicates the malware deletes shadow copies, appends the .KRYBIT extension to encrypted files, and drops a RECOVER-README.txt ransom note. The group has pursued broad, opportunistic victimization across 43 countries, with Germany, Spain, and Brazil among the most affected geographies and professional services, technology, and manufacturing among the most targeted sectors. Public visibility into Krybit increased after rival RaaS operator 0APT breached Krybit’s affiliate panel in April, exposing plaintext credentials, user roles, negotiation data, Tox IDs, and Bitcoin wallets, with leaked records showing about 20 victims in active negotiations and ransom demands ranging from $40,000 to $100,000. Krybit retaliated by compromising and defacing 0APT’s leak site and publishing its operational data, creating a notable ransomware-on-ransomware conflict. Despite the reputational damage and evidence that no confirmed ransom payment had yet been recorded during the leaked period, Krybit continued naming victims through mid-2026 and showed no public signs of shutting down or rebranding.

Jul 13
Socradar

Dark Web Profile: Krybit Ransomware

Jul 12
Lazarusholic Bluesky

Post by @lazarusholic.bsky.social - Bluesky

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.