Skip to content

BlueSky

BlueSky is a Windows ransomware family first observed in 2022 and notable for combining implementation traits associated with Conti and Babuk.

Profile source: Mallory opens in a new tab

BlueSky

Family profile

BlueSky is a Windows ransomware family first observed in 2022 and notable for combining implementation traits associated with Conti and Babuk. Its architecture includes multithreaded file encryption and network-share enumeration resembling Conti, while its cryptographic design uses ChaCha20 for file encryption and Curve25519-based key exchange more closely aligned with Babuk. BlueSky encrypts files on local systems and mounted network shares, appends a distinctive extension to affected files, and drops ransom notes on compromised hosts. It also maintains host-specific state through generated victim identifiers, mutex creation, and registry-stored recovery metadata.

The malware incorporates multiple anti-analysis and defense-evasion measures, including string and API obfuscation, hashed API resolution, and anti-debugging logic. Observed execution chains used staged PowerShell delivery, privilege checks, and local privilege-escalation attempts on different Windows versions, including use of JuicyPotato on older systems and exploitation of CVE-2020-0796 and CVE-2021-1732 on newer systems. In intrusion reporting, BlueSky was deployed after compromise of internet-facing Microsoft SQL Server environments, including cases where attackers brute-forced the MSSQL sa account, enabled command execution through SQL Server features, and then launched PowerShell-based payloads before ransomware deployment.

BlueSky has been associated with broader post-exploitation activity involving Cobalt Strike, SMB-based propagation, credential-dumping activity, and lateral movement via remote service creation. In at least one documented intrusion, ransomware deployment followed initial access in roughly half an hour, indicating a fast hands-on-keyboard operation. Code-level links to Conti and Babuk have been reported, but BlueSky is treated as a distinct ransomware family. Reporting has also noted operational overlap with SQL-server-focused intrusion clusters and possible connections to actors involved in brute-force attacks on exposed MSSQL infrastructure. Victims have included organizations compromised through public-facing Windows server infrastructure rather than a single narrowly defined sector.

Capabilities

  • Brute Force
  • Defense Evasion
  • Exfiltration
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Privilege Escalation
  • Reconnaissance
  • Scanning

Operational record

1
YARA rules
1
Ransom notes
1
Leak sites
0 available

Reported operators

Threat actors

1 named in public reporting
Conti

Executive Summary BlueSky ransomware is an emerging family that has adopted modern techniques to evade security defenses.

Exploited software

Vulnerabilities linked to BlueSky

4 CVEs

MITRE ATT&CK

BlueSky in ATT&CK

13 distinct techniques

Reporting

Research mentioning BlueSky

Jan 1
Sophos Threat Research

OODA: X-Ops Takes On Burgeoning SQL Server Attacks | SOPHOS

Attackers targeted externally exposed, unpatched Microsoft SQL Server systems by exploiting CVE-2019-1068 and CVE-2020-0618, then delivered a mix of malware and ransomware through shared infrastructure and tooling. Sophos linked the intrusions through common ingress methods, command-and-control servers, PowerShell downloaders, a .NET downloader, Remcos RAT, the Kill$ cleaner, and 7zip SFX-based loaders, with ransomware payloads including TargetCompany/Mallox and GlobeImposter/Alpha865qqz. Most victims were observed in Asia, with additional cases in the Americas, and Chinese-language comments in some tools suggested the operators may be based in Asia. In one investigated case, the attackers returned after an earlier ransomware incident because the SQL Server remained unpatched, showing how exposed systems can be repeatedly compromised until the root weakness is fixed. Sophos said its defenses blocked follow-on payload delivery and prevented lateral movement, data exfiltration, and further ransom escalation, while responders also identified IOBit Unlocker as an attempted anti-security utility. Continued traffic to a fake KMSAuto-themed download site helped tie the customer incident to the wider campaign.

Dec 4
Dfir Report

SQL Brute Force Leads to BlueSky Ransomware - The DFIR Report

Attackers brute-forced the sa account on an internet-facing Microsoft SQL Server and escalated a compromise into a full BlueSky ransomware deployment in about 32 minutes. After access was obtained, they enabled xp_cmdshell, launched PowerShell payloads, established a Cobalt Strike beacon, and used Tor2Mine tooling to disable antivirus, create persistence, and install an XMRig-based Monero miner. The intrusion then expanded through remote service creation and SMB activity toward domain controllers and file shares before the ransomware binary, masquerading as vmware.exe, was executed on the initial host. Files were encrypted with the .bluesky extension and a ransom note named # DECRYPT FILES BLUESKY #.txt was dropped, while investigators reported no evidence of data exfiltration. BlueSky is a Windows-focused ransomware family observed since 2022 that has been distributed through phishing emails, phishing sites, and trojanized downloads in addition to direct server compromise. Technical analysis shows the malware adjusts privileges, hides threads from debuggers, creates a mutex, and selectively skips some system-related files and directories while targeting user and database data. It accelerates encryption across local and network resources using multithreading and Windows I/O completion ports, stores recovery-related data in the Windows registry, terminates selected processes before encryption, appends the .bluesky extension to locked files, and generates ransom notes in both TXT and HTML formats.

Oct 14
Cloudsek

Technical Analysis of BlueSky Ransomware | CloudSEK

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.