BabaDeda is a malware crypter and loader service associated with campaigns delivering information stealers, remote access trojans, and ransomware. It was documented in 2021 in operations targeting cryptocurrency and Web3 organizations, and later observed in 2026 campaigns targeting education and financial organizations through ClickFix-style social engineering. In these intrusions, victims are tricked into executing attacker-supplied commands that launch a staged infection chain. BabaDeda evolved from concealing payloads inside legitimate-looking installers into a stealth-focused loader framework designed for staged delivery and in-memory execution. Reported tradecraft includes hidden PowerShell execution, shellcode-based loading, external payload storage, DLL side-loading, host profiling, security-product checks, and process injection into trusted Windows processes. The framework has also been linked to a staged component referred to as Storage Crypter. Payloads delivered through BabaDeda have included a .NET backdoor and information stealer capable of collecting system information, enumerating browser profiles, extracting cookies and saved credentials, reading and exfiltrating files, capturing screenshots, executing commands, and maintaining encrypted command-and-control communications. Separate BabaDeda-linked delivery chains have also been used to deploy DanaBot, SectopRAT, and LockBit ransomware. Reported execution safeguards include avoiding operation on systems associated with Russia or Belarus. BabaDeda is best characterized as a financially motivated malware delivery service supporting credential theft, remote access, and follow-on ransomware activity across multiple victim sectors.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.