Babuk is a ransomware-as-a-service cybercrime operation first publicly observed in early 2021. It became notable for rapid enterprise targeting, support for both Windows and Linux environments, and later for the public leak of its builder and source code, which influenced subsequent ransomware and extortion activity. Babuk has also been associated with the aliases Babuk Locker and Babuk v2.0, and with the later leak-site branding Payload Bin in the period when the group shifted emphasis away from encryption. Babuk targeted organizations across multiple sectors, including manufacturing, transportation, construction and materials, law firms, and government entities. Reported victim geography prominently included the United States, Canada, Spain, France, and Germany, and the group was also linked to the compromise of the Metropolitan Police Department in Washington, D.C. Babuk publicly recruited affiliates on Russian-speaking cybercrime forums and operated under a RaaS model before internal fractures, law-enforcement pressure, and strategic changes contributed to splintering and rebranding activity. Technically, Babuk developed encryptors for Windows and Linux, including VMware ESXi-focused variants intended to impact virtualized enterprise infrastructure. Babuk malware has been documented using ChaCha-family stream ciphers for file encryption and elliptic-curve key exchange, with later variants using Curve25519. The malware commonly used multithreaded encryption, terminated services and processes that could interfere with encryption, deleted shadow copies, inhibited recovery, and encrypted local drives, network shares, and in some variants LAN-accessible resources. Babuk also demonstrated capability to target ESXi environments, reflecting the broader ransomware trend of maximizing impact by encrypting multiple virtual machines through a single hypervisor compromise. Operationally, Babuk combined encryption with data theft and leak pressure, and later announced a move away from device encryption toward pure data-theft extortion. Its leak infrastructure was rebranded as Payload Bin and was positioned as a platform both for Babuk’s own extortion activity and potentially for other actors’ leaks. Babuk’s ecosystem also extended into the Russian-speaking underground through the RAMP forum, which was tied to the same infrastructure lineage and was used to support ransomware-affiliate and access-broker activity. Babuk’s leaked builder could generate Windows, NAS, and ESXi-targeting payloads and corresponding decryptors. The authenticity of the leak was widely assessed as high, and the leak materially lowered barriers for copycats and derivative families. Multiple later ransomware strains and variants were reported to share code or design similarities with Babuk, especially around ESXi targeting and cryptographic implementation. Babuk is therefore significant not only as an operator but also as a progenitor whose leaked tooling contributed to the broader ransomware threat landscape. Babuk is best characterized as a financially motivated Russian-speaking cybercrime actor focused on enterprise ransomware and extortion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
25 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as one of the ransomware groups whose samples The Gentlemen reverse-engineers to improve its own codebase.
Uses DLL sideloading via the legitimate NTSD.exe debugger to deliver ransomware.
Referenced in the context of impersonation/scam behavior: a purportedly resurrected Babuk operation allegedly relisted/copied victims from other ransomware groups to appear active and credible.
Referenced in the context of impersonation/scam activity: a 'resurrected' Babuk-branded operation allegedly relisted/copied victims from other ransomware groups to appear legitimate.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.