Tortilla is a ransomware threat actor active since at least July 2021 that deployed a Babuk-derived ransomware variant against vulnerable Microsoft Exchange servers. The actor is tracked under the name Tortilla based on payload naming and is assessed to have used Babuk source code leaked in 2021 to build its encryptor. Tortilla primarily targeted organizations in the United States, with additional victims observed in Brazil, the Czech Republic, Germany, India, the United Kingdom, Ukraine, Finland, Honduras, and Thailand. The intrusion chain has been associated with exploitation of Microsoft Exchange ProxyShell, followed by deployment of the China Chopper web shell and PowerShell-based staging. Tortilla used staged loaders and in-memory unpacking to deliver the final Babuk payload, including use of an intermediate unpacker and process injection into legitimate Windows processes. The actor employed defense-evasion measures such as AMSI bypasses, disabling Microsoft Defender protections, removing evidence of internet origin from downloaded components, and packing .NET loaders. Prior to ransomware deployment, Tortilla also experimented with additional post-compromise tooling including PowerShell-based utilities. During encryption, the ransomware targeted files on local and mounted drives, deleted Volume Shadow Copy snapshots, and attempted to stop backup-related services to inhibit recovery. Encrypted files were appended with a Babuk-associated extension, and ransom demands were issued for decryption. Analysis of the campaign showed the actor reused a single private key across victims, enabling broad decryption of affected systems with an updated Babuk decryptor. Tortilla is best characterized as a financially motivated ransomware actor rather than a state-sponsored espionage group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
We assess with moderate confidence that the initial infection vector is exploitation of ProxyShell vulnerabilities in Microsoft Exchange Server through the deployment of China Chopper web shell.
The initial downloader is a modified EfsPotato exploit to target proxyshell and PetitPotam vulnerabilities. | EfsPotato is an exploit that attempts to escalate the process privileges using a vulnerability in the Encrypted File System (CVE-2021-36942).
25 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A threat actor operating a Babuk-derived ransomware campaign using the Tortilla variant; victims can be identified by .babyk-encrypted files and the ransom note 'How To Restore Your Files.txt'.
A newly observed ransomware actor deploying Babuk variants, primarily by exploiting vulnerable Microsoft Exchange servers via ProxyShell and deploying China Chopper web shells, then using staged loaders and in-memory unpacking to deliver ransomware.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.