Description
Babuk is a ransomware operation that emerged in 2021 and targeted both corporate networks and smaller victims through compromised remote access services. It exfiltrates data before encryption and threatens publication on a leak site, and it supports Windows systems along with network attached storage devices and VMware ESXi servers. Its source code leaked later in 2021, which allowed cyberattackers to reuse it in new and modified families.
Stats
- First seen
- March 2022
- Last seen
- October 2026
Also known as
Babyk
MITRE ATT&CK techniques
14 techniques across 5 tactics.
Alert name variants
| Alert Name |
|---|
| Gen:Variant.Ransom.Babuk.114 |
| Gen:Variant.Ransom.Babuk.141 |
| Gen:Variant.Ransom.Babuk.157 |
| Gen:Variant.Ransom.Babuk.165 |
| Gen:Variant.Ransom.Babuk.172 |
| Gen:Variant.Ransom.Babuk.44 |
| Gen:Variant.Ransom.Babuk.69 |
| Gen:Variant.Ransom.Babuk.9 |
| Gen:Variant.Ransomware.Linux.Babuk.1 |
| Gen:Variant.Trojan.Linux.Babuk.1 |
